Closed hasherezade closed 5 years ago
0a4962325cf05ea602081647da910866d0d747abbb5d3340dfa721cdd93e9ba5 - Emotet
Emotet has 2 payloads. One of them is reconstructed correctly, while another is not. Both payloads are detected: Header from the payload that is not reconstructed is corrupt (we can see i.e. invalid Machine Id):
After the changes, both payloads are reconstructed correctly. Report: Dumps:
Test case
0a4962325cf05ea602081647da910866d0d747abbb5d3340dfa721cdd93e9ba5 - Emotet
Problem
Emotet has 2 payloads. One of them is reconstructed correctly, while another is not. Both payloads are detected: Header from the payload that is not reconstructed is corrupt (we can see i.e. invalid Machine Id):