Skip to content

Instantly share code, notes, and snippets.

@hasherezade
Last active April 29, 2024 23:34
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save hasherezade/fb91598f6de62bdecf06edf9606a54fb to your computer and use it in GitHub Desktop.
Save hasherezade/fb91598f6de62bdecf06edf9606a54fb to your computer and use it in GitHub Desktop.
Deobfuscates strings from Rhadamanthys (55eef6d7f16da2666adc47b59e1487c5)
c278 'ntdll'
c250 'ZwOpenDirectoryObject'
c228 'ZwQueryDirectoryObject'
c278 'ntdll'
c278 'ntdll'
c278 'ntdll'
c498 'unhook.bin'
c44c 'strategy.x86'
c430 'processes.x'
c418 'ua.txt'
c3bc 'Mozilla/5.0 (Windows NT 10.0; rv:108.0) Gecko/20100101 Firefox/108.0'
c3a4 'dt.x86'
c278 'ntdll'
c504 'proto.x86'
c4e4 'netclient.x86'
c278 'ntdll'
c278 'ntdll'
c520 'phexec.bin'
c56c 'Wow64DisableWow64FsRedirection'
c53c 'Wow64RevertWow64FsRedirection'
c75c 'prepare.bin'
c278 'ntdll'
c808 'ZwAdjustPrivilegesToken'
c9a8 'stage.x86'
c988 'VirtualAlloc'
c96c 'VirtualFree'
c94c 'VirtualProtect'
c92c 'MapViewOfFile'
c90c 'UnmapViewOfFile'
c8f0 'CloseHandle'
c8d4 'early.x64'
c8b8 'early.x86'
cc14 'atcuf32'
cbfc 'bdhkm32'
cbe4 'aswhook'
c278 'ntdll'
ce58 'kernel32'
cde8 'kernelbase'
cd74 'advapi32'
cd08 'ws2_32'
cca0 'combase'
cc2c 'NtTraceEvent'
c278 'ntdll'
ce58 'kernel32'
cde8 'kernelbase'
cd74 'advapi32'
cd08 'ws2_32'
cca0 'combase'
cc2c 'NtTraceEvent'
ce58 'kernel32'
cde8 'kernelbase'
cd74 'advapi32'
cd08 'ws2_32'
cca0 'combase'
c204 \GLOBAL??
c360 ImfRegistryFilter
c33c aswMonFlt
c320 AVGSP
c304 BdNet
c2e0 K7Sentry
c2c4 BdDci
c290 360SelfProtection
c4b4 ws2_32.dll
c46c explorer.exe
c708 %Systemroot%\system32\credwiz.exe
c708 %Systemroot%\system32\credwiz.exe
c708 %Systemroot%\system32\credwiz.exe
c708 %Systemroot%\system32\credwiz.exe
c708 %Systemroot%\system32\credwiz.exe
c778 ABCDEFGHI0123456JKLMNOPQRSTUVWXYZ7890abcdefghijklmnopqrstuvwxyz
c830 --fast
c850 runas
c884 Software\SibCode
c86c sn
c46c explorer.exe
caf4 Global\MSCTF.Asm.{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}
ca50 Session\%u\MSCTF.Asm.{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}
caf4 Global\MSCTF.Asm.{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}
c9c4 MSCTF.Asm.{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}
ce74 \Systemroot\SysWow64\ntdll.dll
ce04 \Systemroot\SysWow64\kernel32.dll
cd90 \Systemroot\SysWow64\kernelbase.dll
cd20 \Systemroot\SysWow64\advapi32.dll
ccb8 \Systemroot\SysWow64\ws2_32.dll
cc4c \Systemroot\SysWow64\combase.dll
cec4 %Systemroot%\system32\dialer.exe
cec4 %Systemroot%\system32\dialer.exe
cec4 %Systemroot%\system32\dialer.exe
cec4 %Systemroot%\system32\dialer.exe
ce74 \Systemroot\SysWow64\ntdll.dll
ce04 \Systemroot\SysWow64\kernel32.dll
cd90 \Systemroot\SysWow64\kernelbase.dll
cd20 \Systemroot\SysWow64\advapi32.dll
ccb8 \Systemroot\SysWow64\ws2_32.dll
cc4c \Systemroot\SysWow64\combase.dll
d068 \Systemroot\system32\kernel32.dll
d010 \Systemroot\system32\kernelbase.dll
cfbc \Systemroot\system32\advapi32.dll
cf6c \Systemroot\system32\ws2_32.dll
cf18 \Systemroot\system32\combase.dll
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment