A riddle posted by recruiters from the israeli internal cyber security services- i guess its a cypher to decode:
MTAxMDAxMTAxMTAxMDAwMDExMDAwMDEwMTEwMDAxMDAxMTAwMDAxMDExMDEwMTEuY29t
It's not a code. It's just what Hebrew sounds like.
>>8863371
My man
Did you decode that cypher?
Did you decode that cipher?
i think it translates to "oy vey palestinian terrorists are genociding us, we must conduct defensive genocide"
>>8863365
1320012413040124132001241320012413040123130405241304012313040523132005231304012413040124132001231304012413040524130405231320052125 20
ez
plz halp
help me i want to hack terrorists
omg i got i got it, it's in UTF-8
10100110110100001100001011000100110000101101011.com
>>8863711
it's a website of some sort, someone should go to it, i don't want the israeli security agency on me
The second site is another challenge with a rar folder..
Inside plane first.exe, I've found an interesting string: %PROGRAMFILES%\meseeker inc
No actual folder has been created, though.
>>8863874
I saw that too.
>>8863946
What are you using?
I just opened up the exe in archive manager.
>>8863956
IDA Pro and X32DBG.
I noticed a call to WriteConsole, followed the external reference to some sub routine responsible for taking a buffer and shifting / printing it. I jumped to it in my debugger and while stepping through the routine it shows unicode jibberish - prolly Hebrew.
How you compiled the file? 0.0
I don't know assembly much, but it seems that this program is decoding an internal code into a message to output.
>>8863946
This guy probably already knows this, but oh well.
>>8864065
By internal code, I mean the encoded string, not actual code.
decompiled with flow charts for easier understanding
https://dropfile.to/tEzb9Yo
>>8863365
This one will be tough. You see, riddles exist on a spectrum...
>>8863365
>MTAxMDAxMTAxMTAxMDAwMDExMDAwMDEwMTEwMDAxMDAxMTAwMDAxMDExMDEwMTEuY29t
Translates to
>Yes the jews did it
But what did they mean by this?
Does anybody have something new ?
>>8864456
Just saw this, plan on working on it when I get home.
The original MTAx etc code is Base64. Translates to that long .com.
it is a threat.
I will arise and kill there god.
they are scared.
Some interesting references:
kernelbase.&RtlIntegerToUnicodeString
kernel32.WideCharToMultiByte
In home base it wants you to compile c++ and run it.