Skip to content

Instantly share code, notes, and snippets.

@hasherezade
Last active December 4, 2023 22:42
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save hasherezade/47fa641d054d82de4059ff36c7e99918 to your computer and use it in GitHub Desktop.
Save hasherezade/47fa641d054d82de4059ff36c7e99918 to your computer and use it in GitHub Desktop.
Rhadamanthys 0.5.0 - taskcore module (decoded strings)
48788 ABCDEFGHIJKLMNOPQRSTUVWXYZ01234567890abcdefghijklmnopqrstuvwxyz
48760 Sec-Websocket-Version
4873c Sec-Websocket-Key
486a4 t
4868c Accept
4866c en-US,en;q=0.9
4864c Accept-Language
4864c Accept-Language
48608 Accept-Encoding
485b0 Mozilla/5.0 (Windows NT 10.0; rv:108.0) Gecko/20100101 Firefox/108.0
48594 User-Agent
48578 websocket
48560 Upgrade
48548 upgrade
4852c Connection
48518 13
488d0 CorBindToRuntime
488b0 GetCORVersion
48888 GetRequestedRuntimeInfo
488f4 CLRCreateInstance
48930 CorBindToRuntimeEx
48380 user32
48d78 Default
48d98 RHMTHYS
48d98 RHMTHYS
483d8 WScript
483b0 Rhadamathys
483f8 %Systemroot%\system32\wscript.exe
483d8 WScript
483b0 Rhadamathys
48494 AddPkgData
4846c AddPkgFile
4844c Version
484bc 0.5.0
48800 \Registry\Machine\SOFTWARE\Microsoft\Cryptography
487d8 MachineGuid
48918 wks
48984 mscoree.dll
489d0 Runtime
489ac CoreMain
489d0 Runtime
489ac CoreMain
48b78 Dumpper
48c1c \Systemroot\system32\win32u.dll
48330 \Systemroot\system32\user32.dll
48d00 powershell
48d58 plugins
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment