Skip to content

hackingump/malwareStuff

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

13 Commits
 
 
 
 
 
 
 
 

Repository files navigation

malwareStuff

Danabot Deobfuscation

The text file contains hashes computed by the DanaBot API Hashing algorithm and can be used for deobfuscation purposes.

Each entry has the following format:

[DLL]---[OFFSET_IN_DLL]---[FUNC_NAME]---[ORDINAL]---[API_HASH]

Hashes for the following libraries were generated:

ole32.dll
api-ms-win-core-synch-l1-2-0.dll
gdi32.dll
urlmon.dll
api-ms-win-core-sysinfo-l1-2-1.dll
comctl32.dll
api-ms-win-crt-runtime-l1-1-0.dll
rpcrt4.dll
shlwapi.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
winhttp.dll
advapi32.dll
crypt32.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
ntdll.dll
winmm.dll
wininet.dll
uxtheme.dll
msvcrt.dll
kernel32.dll
IPHLPAPI.DLL
user32.dll
api-ms-win-core-localization-l1-2-1.dll
netapi32.dll
KernelBase.dll
mpr.dll
oleaut32.dll
comdlg32.dll
setupapi.dll
psapi.dll
msvcp60.dll
api-ms-win-core-fibers-l1-1-1.dll
userenv.dll
XpsPrint.dll
version.dll
shell32.dll
ws2_32.dll
wsock32.dll

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors