Strings & hashes of a (defanged) sampleeasynot started
A harmless, self-made pseudo-sample (sample.bin — NO real malicious code) has suspicious strings embedded. Extract the strings, find the encoded C2 URL and the flag, and verify the file's SHA-256 matches the provided IOC.
1. Load sample.bin in the in-page analyzer (or run strings sample.bin). Among the strings is a base64 blob. Why: static strings often reveal URLs, keys and messages without running the file.
2. Base64-decode the blob (page decoder): it contains the C2 URL and the flag THM{...}.
3. Confirm the file's SHA-256 (computed in-page) equals the IOC shown. Why: hashes identify known samples.
This sample is 100% benign (plain data). Lesson: static analysis is safe and fast first-pass triage.