Summary
Sample hash is: fc345d151b44639631fc6b88a979462dfba3aa5c281ee3a526c550359268c694
This write-up of mine will be divided into three parts:
- Grab core Emotet Dll payload.
- Recover API functions that used by core payload.
- Decrypt strings
M | T | W | T | F | S | S |
---|---|---|---|---|---|---|
1 | 2 | 3 | 4 | 5 | ||
6 | 7 | 8 | 9 | 10 | 11 | 12 |
13 | 14 | 15 | 16 | 17 | 18 | 19 |
20 | 21 | 22 | 23 | 24 | 25 | 26 |
27 | 28 | 29 | 30 | 31 |
Sample hash is: fc345d151b44639631fc6b88a979462dfba3aa5c281ee3a526c550359268c694
This write-up of mine will be divided into three parts: