pan-unit42 / dotnetfile

MIT License
97 stars 16 forks source link

Incomplete Dotnet Resourse Parsing? #10

Closed utkonos closed 4 months ago

utkonos commented 1 year ago

This first screenshot is parsing a dotnet resource from a malicious file using YARA to find the offset and size and then dump that location.

image2

The last cell shows the start of the ICO icon and then the PNG image data.

And here is a screenshot of dotnetfile parsing the same file.

image1

There appears to still be some dotnet-looking header data between the start of the "data" and the ICO icon.

Is this header structure able to be parsed? The sample in question in both screenshots is: 40cd96e25835eeba956645398ed73a0f0e14563375530fa5f2db3bcf44dd88d7