Slide 50
Slide 50 text
The XS format
• We were able to create a tool that can convert
an XS component, dumped from memory, into a PE
Reconstructed PE
header
Normalized
sections layout
Converted data
directories:
relocations,
imports, etc
Deobfuscated,
easily parsable
imports
Converter:
https://github.com/hasherezade/hidden_bee_tools/
tree/master/bee_lvl2_converter