Threat Level: green Handler on Duty: Remco Verhoef

SANS ISC: IP Address from Hex SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network
https://isc.sans.edu/honeypot.html

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
IP Address from Hex
The diary entry "Fileless Malicious PowerShell Sample" (https://isc.sans.edu/forums/diary/Fileless+Malicious+PowerShell+Sample/23081) helped me with some malware I am analyzing however I have gotten to the second part of the post where the embedded code needs to be disassembled to understand what is going on.

The anonymous poster in this entry shared the disassembled code. I have a basic understanding of assembly language but not this level.

Could someone share how you find the IP address from the given line?

0x000000b2 6802000a98 push 0x980a0002--> IP 213.184.123.143:2712

Thank you
Anonymous

Sign Up for Free or Log In to start participating in the conversation!