"The "taskmgr.exe" embedded from offset 0x24E00. The exe is XOR'ed with 64 bit key 0xCA5039AF00000000. If you XOR the file again with same key you'll find the exe headers at offset 0x24E00." Please see the screenshot below.
To read full analysis and download samples please follow Mila's blog:: http://contagiodump.blogspot.com/2010/02/feb-22-ms-word-taiwan-2010-from.html
No comments:
Post a Comment