Forensic Blogs

An aggregator for digital forensics blogs

November 5, 2014 by Didier Stevens

XORSearch: Hexdump Support

Sometimes I want to check a malware sample with XORSearch, but I can’t because my AV will delete it. My solution is to work with a hexdump of the file.

Option -x allows XORSearch to work with a hexdump.

XORSearch_V1_11_1.zip (https)
MD5: D5EA1E30B2C2C7FEBE7AE7AD6E826BF5
SHA256: 15E9AAE87E7F25CF7966CDF0F8DFCB2648099585D08EAD522737E72C5FACA50A


Read the original at: Didier StevensFiled Under: Uncategorized Tagged With: My Software, Update

  • « Previous Page
  • 1
  • …
  • 195
  • 196
  • 197

About

This site aggregates posts from various digital forensics blogs. Feel free to take a look around, and make sure to visit the original sites.

  • Contact
  • Aggregated Sites

Suggest a Site

Know of a site we should add? Enter it below

Sending

Jump to Category

All content is copyright the respective author(s)