Powershell and DnSpy tricks in .NET reversing - AgentTesla [Part2]

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ต.ค. 2024

ความคิดเห็น • 11

  • @Stack28x3
    @Stack28x3 ปีที่แล้ว +1

    it is a gift from the gods... Thank you

  • @pamarthinagarjuna
    @pamarthinagarjuna 2 หลายเดือนก่อน

    Showing below error in Powershell sir.. Please suggest..
    Unhandled Exception: System.IO.FileNotFoundException: Could not load file or assembly 'System.Private.CoreLib, Version=8.0.0.0, Culture=neutral, PublicKeyToken=7cec85d7bea7798e' or one of its dependencies. The system cannot find the file specified.

  • @fikrahack
    @fikrahack 2 ปีที่แล้ว

    الأفضل

  • @mennaosama9313
    @mennaosama9313 2 ปีที่แล้ว

    De4dot result when replacing decrypted strings
    de4dot v3.1.41592.3405
    Detected Unknown Obfuscator (C:\Users\User\Desktop\Extra Tools\de4dot\final_payload.bin)
    Cleaning C:\Users\User\Desktop\Extra Tools\de4dot\final_payload.bin
    ERROR:
    ERROR:
    ERROR:
    ERROR: Hmmmm... something didn't work. Try the latest version.
    It it the same version of de4dot
    Can you provide de4dot exe used? Or recommend a solution?

    • @DuMpGuYTrIcKsTeR
      @DuMpGuYTrIcKsTeR  2 ปีที่แล้ว

      Could you provide more context, for example DM me on twitter (cmdline you used and sample) ? I used the same version of de4dot as you.

    • @mennaosama9313
      @mennaosama9313 2 ปีที่แล้ว

      @@DuMpGuYTrIcKsTeR I am using the same sample you are using.
      I tried to use the command for one token only ".\de4dot.exe final_payload.bin --strtyp delegate --strtok 0600022e" to check if something wrong with the long command but it didn't work too.

    • @DuMpGuYTrIcKsTeR
      @DuMpGuYTrIcKsTeR  2 ปีที่แล้ว

      @@mennaosama9313 Well there must be really something wrong with your version of de4dot as I cant reproduce. Here is my original version which works. Try it and let me now. www7.zippyshare.com/v/pKP1mYzh/file.html

    • @DuMpGuYTrIcKsTeR
      @DuMpGuYTrIcKsTeR  2 ปีที่แล้ว

      @@mennaosama9313 MD5 hash of the uploaded archive: 1EF7606AF0152A924CF15EC754D57DBD

    • @mennaosama9313
      @mennaosama9313 2 ปีที่แล้ว

      @@DuMpGuYTrIcKsTeR Thank you so much and thank you for this video it helped a lot