Evil MSI Background: BASE64 Statistical Analysis, (Mon, Jun 15th)
ID: de25c3a5-731f-55fd-bd22-5fc7910d8a3b
STIX ID: report--de25c3a5-731f-55fd-bd22-5fc7910d8a3b
Feed Name: SANS ISC Diary
Threat Score
A technical walkthrough demonstrating the discovery and extraction of a Windows PE executable embedded in a JPEG via a custom Base64-like encoding and reversal. The author uses and enhances tools (byte-stats.py, base64dump.py with a new --stats option, translate.py) to identify character substitution and reversed encoding, reverse the payload, and confirm the extracted PE matches a previously-observed sample.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
