2023年9月11日Let’s take a look at more of the malware payload. Maybe we can figure out what it’s doing. It looks like it’s usingesias its base of operations, so let’s disassemble fromesi. 008bf684 push ebp ; build stack frame 008bf685 mov ebp,esp 008bf687 push ebx ; save ebx 008bf688...
D# A# E D# B 99 bottles of beer (as compressed MIDI & encoded as Base64) UEsDBBQAAAAIAPZKglfQhke5TgUAAJduAAALAAAAOTliZWVyLm1pZGntXMltFUEQHQsJ0iADErAt7z75gOQAOHBAQuJAAoBIwCmQGZkYz+XpS0961NbLjP+t9H9PL9W1vFpmHh6/fF6W5e1yspyc/H14/P51Wb79Wp4/vnn35/3ydP3j96ef1xfL09VKXL0Qpytx2...