Skip to content

Instantly share code, notes, and snippets.

@arunl
arunl / vpnfilter-x86-stage2.csv
Created July 12, 2018 20:32
Bindiff of x86 VPNfilter files
procedure id #instructions #samples inYara? 4abb20f92c04e1118e356936f36359620e998de7 60a5b825c197a8788b8934c31e7453bd9a87e452 8a189f0c6a69efeaed1916860a0ff74e424563f6
00045e1473d3e079d62ff2a93f784f63 45 2 False 0x9fc0 - 0x9290
003188505f8c8bc8646a8cf5b714326b 17 3 False 0x27ba0 0x26ec0 0x26c90
00521f8e7a3982730dd1b56636696a01 75 1 False 0x5cd0 - -
005b96764296970b2cf3b51e93678ddd 113 3 True 0x36d08 0x35f78 0x35cb0
00de8002cdf29be10e773df55d7c30c6 27 3 True 0x1eb00 0x1de20 0x1dbf0
01000f4f2da8269e7821a72030c89824 8 2 False - 0x33d68 0x33b38
0134b1a741bd76b0e9ad4a59ce48e10b 11 3 False 0x11ab0 0x10f40 0x10d10
01455609f1197db2750872b2dc0bd2e3 100 3 True 0x384d4 0x37688 0x373c0
014d75c05ad8227c4e565ecef41de507 58 2 True - 0x5dc0 0x5b90
@arunl
arunl / vpnfilter-yara-matches.csv
Last active July 10, 2018 00:20
Matches from VPN Filter Yara Rules
Arch/Stage Sha1 Family
ARM Stage 2
f16c48ead435d2574abd2e18836681ba2ce788e7 VPNFilter
12fcf1e988139160f3c8d6b07e05417e32defee5 PNScan
5a0416cffd5aa8273b2daf18b6eece0ee2d65724 PNScan
8c9fd0c2f8795a25392d03f00766691c9f209ddd PNScan
a3b36e0af923edc0939a38ac4a1a7fea52766984 PNScan
0e169f77716c32c8e8de0032f1c66d57775c3638 PNScan
X86 Stage 1
4ac8d962c6072b77f157c5d6459b887a658d66d5 VPNFilter
@arunl
arunl / vpnfilter-clusters.csv
Last active July 9, 2018 23:36
vpnfilter-clusters
Architecture Talos count Num of Distinct Procedures Distribution type # Shared Procedures % Procedures Shared
ARM 2 472 In both files 465 98.51%
In 1 file 7 1.49%
MIPS 3 780 In all 3 files 567 72.69%
In 2 files 100 12.82%
In 1 file 113 14.49%
X86 3 791 In all 3 files 628 79.40%
In 2 files 62 7.83%
In 1 file 101 12.76%