{"id":8158,"date":"2022-07-22T20:40:00","date_gmt":"2022-07-22T20:40:00","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=8158"},"modified":"2022-07-22T20:40:00","modified_gmt":"2022-07-22T20:40:00","slug":"week-of-data-dumps-part-2-guids","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2022\/07\/22\/week-of-data-dumps-part-2-guids\/","title":{"rendered":"Week of Data Dumps, Part 2 \u2013 GUIDs"},"content":{"rendered":"\n<p>There was a time when knowing GUIDs of adware\/spyware you could instantly attribute a sample to a known rogue company or group. Of course, these days are long gone, but what&#8217;s left behind is knowledge which GUIDs map to what&#8230;<\/p>\n\n\n\n<p>GUIDs are all over the place &#8211; there are CLSIDs, UUIDs, they can refer to classes, interfaces, object properties, known folder IDs, even old ActiveX controls and IE toolbars, and new ones keep coming in ! So how do we know which ones are important?<\/p>\n\n\n\n<p>My recipe was to always collect as many of these as possible!<\/p>\n\n\n\n<p><a href=\"https:\/\/hexacorn.com\/d\/hjt_guids.txt\">This is a small excerpt<\/a> from some quick regex-fu over HijackThis Logs. And <a href=\"https:\/\/hexacorn.com\/d\/guids.txt\">here<\/a> is a list of GUIDs I have built over the years.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There was a time when knowing GUIDs of adware\/spyware you could instantly attribute a sample to a known rogue company or group. Of course, these days are long gone, but what&#8217;s left behind is knowledge which GUIDs map to what&#8230; &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2022\/07\/22\/week-of-data-dumps-part-2-guids\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[53,39,21],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8158"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=8158"}],"version-history":[{"count":5,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8158\/revisions"}],"predecessor-version":[{"id":8168,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8158\/revisions\/8168"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=8158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=8158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=8158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}