@thehellu Great analysis!
Would like to just point out one minor oversight in the report:
The bytes 08 08 08… are not a hard-coded delimiter. They are instead the 4 DNS lookup IP addresses used to resolve C2 domains:
8.8.8.8
8.8.4.4
4.4.4.4
4.2.2.2
Time has been scarce recently.. happy to still complete #flareon9 much faster than last year. Thanks @nickharbour and rest of the FLARE team.
Looking forward to next year!