Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dumps names from memdump.*.metadata files are not compatible with the real content of ZIP file #638

Open
catsuryuu opened this issue Sep 14, 2021 · 0 comments
Labels
bug Something isn't working certpl Fix requested by CERT.PL team

Comments

@catsuryuu
Copy link
Member

Dumps names from memdump.*.metadata files are not compatible with the real content of ZIP file.
There is no inclusion in either direction.

Example analysis:
analysis_id: c25dcf7e-b045-4afd-a561-aecd617313b6
sample: ec9acfffc18f89d2075d1db988a73d072aa1c227f7076cc6faaf1c9b15fcd6db

Dump names not existing in memdump.*.metadata files:

  • 2460000_2dbde0eb94fc0635 (19488768 B)
  • 2460000_3cfc3b31ee4fe4d5 (19488768 B)
  • 2460000_b55bbe7cb9af2fdb (19488768 B)

Dump names existing in memdump.*.metadata files only:

  • 8bf000_3d216e7de4250e56 (4 B)
    (in memdump.000002.metadata, memdump.000003.metadata, memdump.000016.metadata, memdump.000017.metadata)
  • maybe more...
@catsuryuu catsuryuu added bug Something isn't working certpl Fix requested by CERT.PL team labels Sep 14, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working certpl Fix requested by CERT.PL team
Projects
None yet
Development

No branches or pull requests

1 participant