I added function ZlibRawD to translate.py to decompress Zlib compression without header (ZlibD already exists, and is for Zlib compression with header).
This compression is sometimes used in malicious PowerShell scripts:
translate_v2_5_5.zip (https)
MD5: 0BBB0E7E569BCB08D5A9278C974A3EE6
SHA256: 78E0BAC87DF47D06BB9C351FBF3CA623EE10B3993E071E7C9A0C9C4DB0FFF1D4
[…] Update: translate.py Version 2.5.5 […]
Pingback by Title: Overview of Content Published in February | Didier Stevens — Saturday 2 March 2019 @ 0:00
[…] Update: translate.py Version 2.5.5 […]
Pingback by Week 9 – 2019 – This Week In 4n6 — Sunday 3 March 2019 @ 6:35