We added support for detecting executables ciphered with bitwise shift ciphers - ROR (shift right) and ROL (shift left) which was first reported from a sample from Mila's blog (contagiodump). Bitwise shifts are similar to multiple or division by 2's. This sample used a shift left of one position (rol 1) along with a 256byte XOR key.
Overview of Content Published in August
-
Here is an overview of content I published in August: Blog posts: Update:
pdf-parser.py Version 0.7.13 SANS ISC Diary entries: Wireshark 4.4.9
Released pdf...
1 week ago
No comments:
Post a Comment