A decoder for the SUNBURST DGA malware DNS traffic
Find a file
Neale Pickett 3e0413f9f7 Much cleaner Esab32 decoding
Tries all permutations of chunks in Esab32,
until it gets only printable characters.
This decodes all but one line of the data
I currently have:
that GUID is successfully decoded
later after another chunk is added.
So this is 100% successful.
2020-12-22 21:45:30 -07:00
.gitignore subst reconstitution is broken 2020-12-22 17:59:54 -07:00
Makefile subst reconstitution is broken 2020-12-22 17:59:54 -07:00
NOTES.md subst reconstitution is broken 2020-12-22 17:59:54 -07:00
sunburst.py Much cleaner Esab32 decoding 2020-12-22 21:45:30 -07:00