Closed mr-tz closed 3 years ago
I have two test programs that invoke BITS via COM (both were compiled from Microsoft's C++ example code) and these byte sequences don't appear to be present in either... Here are those programs in case you were interested in taking a look at why:
I've shortened the byte sequences. See my edit above. Do these appear?
5ce34c0d-0dc9-4c1f-897c-daa1b78cee7c
4991d34b-80a1-4291-83b6-3328366b9097
with the edit, the first two sequences appear. the third sequence is not present in BITSDownload.exe
.
would be nice to have a format for GUIDs/COM:
For reference, BITSDownload.exe
is verbatim from [1] but with the list of things to download modified to only pull down http://www.msftconnecttest.com/ncsi.txt
and save in c:\\TEMP\\bits_download-nsci.txt
@recvfrom could you please share the files again or upload one/both to https://github.com/fireeye/capa-testfiles?
Ah yep, sorry about that - I forgot that those share links have really short expiration times. Try this one:
Thanks! Added an according rule in #377.
EDIT: shortened bytes