Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detects x-msdownload mime type but does not extract it #16

Open
beyefendi opened this issue Dec 28, 2016 · 0 comments
Open

Detects x-msdownload mime type but does not extract it #16

beyefendi opened this issue Dec 28, 2016 · 0 comments

Comments

@beyefendi
Copy link

In tcp stream 2, 3, and 4 there are binaries that have content type <application/x-msdownload>.
Captipper finds them pretty fine, however neither <dump all> nor <-d> switch does not export those files.

In addition to that there is also another bug in this sample.
There are two requests to the following URL path, however CapTipper catches only one of them, particularly the first one.

URL

/?es_sm=108&oq=xfR7L7VUbwq0hBfTewFllYxYA1pGoauojkXQnEOd1JGK_xWJYAsR96KlJLR_mhj2&aqs=chrome.113j102.406q9m8&q=w3rQMvXcJxvQFYbGMvnDSKNbNk_WHViPxo6G9MildZ-qZGX_k7PDfF-qoVvcCgWR&sourceid=chrome&ie=Windows-1252 

Sample

http://www.malware-traffic-analysis.net/2016/12/13/2016-12-13-pseudoDarkleech-Rig-V-sends-Cerber-ransomware.pcap.zip
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant