Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@Gibson:~# file 2058.XIA
- 2058.XIA: Zip archive data, at least v2.0 to extract
- So It's a ZIP file essentially, and if we try to extract it we get this.
- root@Gibson:~# unzip 2058.XIA
- Archive: 2058.XIA
- [2058.XIA] b.wnry password:
- It's password protected, BUT going through the assembler we see that it tried to add an parameter to the stack, so after changing the signature from undefined4 FUN_00401dab (HMODULE param_1,) to undefined4 FUN_00401dab (HMODULE param_1, char * param_2) we get this. FUN_00401dab((HMODULE)0x0,s_WNcry@2ol7_0040f52c);
- So we try WNcry@2ol7 as the password for the ZIP file.
- root@Gibson:~# unzip -P WNcry@2ol7 2058.XIA
- Archive: 2058.XIA
- inflating: b.wnry
- inflating: c.wnry
- inflating: msg/m_bulgarian.wnry
- inflating: msg/m_chinese (simplified).wnry
- inflating: msg/m_chinese (traditional).wnry
- inflating: msg/m_croatian.wnry
- inflating: msg/m_czech.wnry
- inflating: msg/m_danish.wnry
- inflating: msg/m_dutch.wnry
- inflating: msg/m_english.wnry
- inflating: msg/m_filipino.wnry
- inflating: msg/m_finnish.wnry
- inflating: msg/m_french.wnry
- inflating: msg/m_german.wnry
- inflating: msg/m_greek.wnry
- inflating: msg/m_indonesian.wnry
- inflating: msg/m_italian.wnry
- inflating: msg/m_japanese.wnry
- inflating: msg/m_korean.wnry
- inflating: msg/m_latvian.wnry
- inflating: msg/m_norwegian.wnry
- inflating: msg/m_polish.wnry
- inflating: msg/m_portuguese.wnry
- inflating: msg/m_romanian.wnry
- inflating: msg/m_russian.wnry
- inflating: msg/m_slovak.wnry
- inflating: msg/m_spanish.wnry
- inflating: msg/m_swedish.wnry
- inflating: msg/m_turkish.wnry
- inflating: msg/m_vietnamese.wnry
- inflating: r.wnry
- inflating: s.wnry
- extracting: t.wnry
- inflating: taskdl.exe
- inflating: taskse.exe
- inflating: u.wnry
- It works!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement