View Single Post
  #11  
Old 29-08-2023, 05:38
L33THAK0R's Avatar
L33THAK0R L33THAK0R is offline
Registered User
 
Join Date: Feb 2021
Location: Saudi Arabia
Posts: 406
Thanks: 137
Thanked 117 Times in 70 Posts
L33THAK0R is on a distinguished road
Quote:
Originally Posted by Masquerade View Post
No, I meant the oo2scan_7_win64.exe by Razor12911, as it lists these algorithms:

Code:
Universal Oodle stream scanner

Created by Razor12911

[0] = Unknown/Invalid
[1] = Kraken/Hydra
[2] = Mermaid/Selkie/Hydra
[3] = Leviathan/Hydra
If you scan and you see [1] appearing, it could be that you are seeing Hydra streams, not kraken.

Try extracting a single stream from the sample you are testing on using XTool verbose output and a Hex editor and attempt to pre-compress it with oo2reck. If it *is* a Kraken stream, it will be inflated. Otherwise, try Hydra.
I'm seeing results for both [1] and [3], however using XTool's GUI and testing each library against the sample, now with both the Kraken and Hydra codecs, still results in the same number of streams being successfully pre-compressed, when compared to only using Kraken. I've got a feeling it may in this case be Leviathan & Kraken, and I'm aware of how annoying Leviathan is to process since theres a notable manual element to pre-compressing this Oodle variant. I might investigate this title further, at some point in the future, once I'm more confident with working with undocumented Oodle titles.
Reply With Quote