4 ms·
> no winhttp.dll, wininet.dll, or ws2_32.dll. offline validation only. all crypto is local, so theoretically extractable. You can't possibly know that by the m
by kaszanka 10mo ago
> no winhttp.dll, wininet.dll, or ws2_32.dll. offline validation only. all crypto is local, so theoretically extractable.
You can't possibly know that by the mere lack of these DLLs from the import directory.
- muststopmyths 10mo agoTFA is checking those via imports, not copied DLLs. I suppose they could LoadLibrary/GetProcAddress at runtime, but that'd be a lot of effort for obfuscation.