View Single Post
  #10  
Old 28-08-2023, 08:29
Masquerade Masquerade is offline
Registered User
 
Join Date: Jan 2020
Location: Monte d'Or
Posts: 1,217
Thanks: 294
Thanked 1,404 Times in 637 Posts
Masquerade is on a distinguished road
No, I meant the oo2scan_7_win64.exe by Razor12911, as it lists these algorithms:

Code:
Universal Oodle stream scanner

Created by Razor12911

[0] = Unknown/Invalid
[1] = Kraken/Hydra
[2] = Mermaid/Selkie/Hydra
[3] = Leviathan/Hydra
If you scan and you see [1] appearing, it could be that you are seeing Hydra streams, not kraken.

Try extracting a single stream from the sample you are testing on using XTool verbose output and a Hex editor and attempt to precompress it with oo2reck. If it *is* a Kraken stream, it will be inflated. Otherwise, try Hydra.
Reply With Quote
The Following User Says Thank You to Masquerade For This Useful Post:
L33THAK0R (28-08-2023)