Malware Devil

Sunday, October 25, 2020

Video: Pascal Strings, (Sun, Oct 25th)

Programs written in the Object Pascal (Delphi) programming language, have their strings stored in the executable file as Pascal strings. A Pascal string (or P-string) is a string that is internally stored with a length-prefix: an integer that counts the number of characters inside the string.

When analyzing Delphi malware, it is useful to extract its Pascal strings (in stead of extracting all strings). You can do this now with an update to my strings.py tool.

I’ve also recorded a video showing this new feature:

Didier Stevens
Senior handler
Microsoft MVP
blog.DidierStevens.com DidierStevensLabs.com

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Read More

The post Video: Pascal Strings, (Sun, Oct 25th) appeared first on Malware Devil.



https://malwaredevil.com/2020/10/25/video-pascal-strings-sun-oct-25th/?utm_source=rss&utm_medium=rss&utm_campaign=video-pascal-strings-sun-oct-25th

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...