|
|
|
|
|
by BirbSingularity
891 days ago
|
|
Hey there. I must have missed the section that handles encrypting the session key, my bad. It's more the struct method of embedding though that I was emphasizing. Structured encrypted data has high entropy which can give away it's presence. Try running some of your before and after images through aperisolve or the cyberchef entropy analysis tool and see how the analysis changes. https://www.aperisolve.com/ https://gchq.github.io/CyberChef/#recipe=Entropy('Curve') |
|
Original: https://cloud.screenpresso.com/g5MIc/2024-01-25_01h15_08.png
With hidden data: https://cloud.screenpresso.com/lIvFc/2024-01-25_01h11_22.png
The differences appear to be on the right side of the spectrum, which I assume is the end of the file where the hidden data is stored. The CyberChef tools are awesome, thanks!
Here are the Aperisolve results:
https://www.aperisolve.com/1f1b2593242e7e690101155741f40aa0
Aside from the string results, everything seems normal here.