Skip to content

Commit

Permalink
Grammar and formatting
Browse files Browse the repository at this point in the history
  • Loading branch information
ryan-weil committed May 16, 2024
1 parent 22d91bf commit bd8279b
Show file tree
Hide file tree
Showing 3 changed files with 11 additions and 13 deletions.
20 changes: 9 additions & 11 deletions _posts/2024-02-25-AGENT-TESLA-1.md
Original file line number Diff line number Diff line change
Expand Up @@ -275,16 +275,14 @@ Opening the dumped file in dnSpy confirms that it is indeed Agent Tesla
![alt text](/images/at1/image-56.png)
_Figure 53_

Stay tuned for part two where we will be removing Agent Tesla's control flow flattening by writing our own de4dot plugin!
I recommend [checking out my next post](https://ryan-weil.github.io/posts/AGENT-TESLA-2/) where I demonstrate how to remove Agent Tesla's control flow flattening by writing a de4dot plugin!

## IOC MD5's
## IOCs

Initial File/Stage One: B89F6062D174E452D189EC4248AF489C

DeclareTextBoxValue.dll: 08ed70a40aa366a9d6e21cba736f4435

ReactionDiffusion.dll: 440bb4db146ccb1161ac2bcf365d7676

Tyrone.dll: a2f3cd39918ea671f5c983eccfd004d2

Agent Tesla: 624b552d1e7457a345f89b6aa1d6c75b
| File | MD5 |
| -------- | ------- |
| Initial File/Stage One | B89F6062D174E452D189EC4248AF489C |
| DeclareTextBoxValue.dll | 08ed70a40aa366a9d6e21cba736f4435 |
| ReactionDiffusion.dll | 440bb4db146ccb1161ac2bcf365d7676 |
| Tyrone.dll | a2f3cd39918ea671f5c983eccfd004d2 |
| Agent Tesla Payload | 624b552d1e7457a345f89b6aa1d6c75b |
2 changes: 1 addition & 1 deletion _posts/2024-02-28-AGENT-TESLA-2.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ categories: malware

## Introduction

In the [previous post](https://ryan-weil.github.io/posts/AGENT-TESLA-1/), we successfully unpacked Agent Tesla. We left off on a bit of a cliffhanger though, because after opening it in dnSpy it was apparent that it had control flow flattening applied. At first glance it doesn't look too unreadable:
In the [previous post](https://ryan-weil.github.io/posts/AGENT-TESLA-1/) we successfully unpacked Agent Tesla. We left off on a bit of a cliffhanger though, because after opening it in dnSpy it was apparent that it had control flow flattening applied. At first glance it doesn't look too unreadable:

![alt text](/images/at2/first.png)
_Figure 1_
Expand Down

0 comments on commit bd8279b

Please sign in to comment.