Sentinel-One/CobaltStrikeParser

UnicodeDecodeError / Punycode

ssnkhan opened this issue · 3 comments

Getting the following error when attempting to parse a Beacon:
UnicodeDecodeError: 'utf-8' codec can't decode byte 0xf6 in position 0: invalid start byte

MD5 3d919f663d6201c66572ee4510699864
SHA-1 7bd34858fcce27bc7ac6149b033e535ae6ba4152
SHA-256 c69c750a2dda1a73b7e0c2e8c85db2a71315ebb6e137d17d7aa293a766058332

https://www.virustotal.com/gui/file-analysis/M2Q5MTlmNjYzZDYyMDFjNjY1NzJlZTQ1MTA2OTk4NjQ6MTY2ODUwNDI4NA==

pDNS

xn--sf-eka[.]digital
vpn2[.]xn--sf-eka[.]digital
certificate[.]xn--sf-eka[.]digital
xn--sf-1ja[.]digital
community[.]xn--sf-eka[.]digital
dev[.]xn--sf-eka[.]digital
learninghub[.]xn--sf-eka[.]digital
signature[.]xn--sf-eka[.]digital

The umlaut appears to be causing the issue: ösf[.]digital.

First time seeing this type of error.

Oh great catch. Thanks for opening a ticket for it! will be fixed shortly.

@ssnkhan Fixed. Please pull and test

Working wonderfully, thanks @Kristal-g :)