Skip to content

Instantly share code, notes, and snippets.

import sys, base64
file = open(sys.argv[1], "rb")
data = file.read()
start = b'$OO00O0000='
end = b';eval'
length = int(data[data.find(start) + len(start) : data.find(end)], 16)
@kernelm0de
kernelm0de / colibri_decoded_strings.txt
Created March 24, 2022 09:54
Colibri Loader Strings
check
ping
32bit
update
%s\SysWOW64\regsrv32.exe
%s\System32\regsrv32.exe
/vpnchecker.php
cmd.exe
powershell.exe -windowstyle hidden
runas