Buster_BSA wrote:You can get it from: http://hotfile.com/dl/119929569/86e5b8a ... I.RAR.htmlAccording to MD5 it differs from the previous version. Could you please explain what you have imlemented?
A forum for reverse engineering, OS internals and malware analysis
Buster_BSA wrote:You can get it from: http://hotfile.com/dl/119929569/86e5b8a ... I.RAR.htmlAccording to MD5 it differs from the previous version. Could you please explain what you have imlemented?
gjf wrote:According to MD5 it differs from the previous version. Could you please explain what you have imlemented?When you compile a source the timestamp fields change, that´s why the MD5 is different.
Buster_BSA wrote:You can get it from: http://hotfile.com/dl/119929569/86e5b8a ... I.RAR.htmlthx, 100% detected
kmd wrote:Could you share the binary to make tests on my end, please?Buster_BSA wrote:You can get it from: http://hotfile.com/dl/119929569/86e5b8a ... I.RAR.htmlthx, 100% detected
Could you share the binary to make tests on my end, please?sent via pm
kmd wrote:@BusterSend me a private message with the stuff you found, please.
Just in case if u interested. I found several other simple ways to detect ur lib. As in fact there no hiding (real or partial) in this log_api.dll version.
Send me a private message with the stuff you found, please.thing are obvious: