<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh" -->

---
title: Einladen mso.dll Reverse Engineering | daily.dev
description: This post explores the Einladen Sherlock malware and the analysis of the dropped DLLs, including msoev.exe and mso.dll. It covers the purpose of msoev.exe, the...
canonical: https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Einladen mso.dll Reverse Engineering | daily.dev
og:description: This post explores the Einladen Sherlock malware and the analysis of the dropped DLLs, including msoev.exe and mso.dll. It covers the purpose of msoev.exe, the...
og:url: https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh
og:image: https://api.daily.dev/og/posts/u4xdUqqGH.png
og:image:alt: Einladen mso.dll Reverse Engineering
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Einladen mso.dll Reverse Engineering

**[0xdf hacks stuff](https://daily.dev/sources/0xdf)** · 7 min read · 0 upvotes · 0 comments

## Summary

This post explores the Einladen Sherlock malware and the analysis of the dropped DLLs, including msoev.exe and mso.dll. It covers the purpose of msoev.exe, the imports of mso.dll, and the method of loading wininet.dll.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://0xdf.gitlab.io/2024/05/09/htb-sherlock-einladen-malware-re.html>

---

Tags: [#microsoft](https://daily.dev/tags/microsoft), [#malware](https://daily.dev/tags/malware), [#reverse-engineering](https://daily.dev/tags/reverse-engineering)

[View this post on daily.dev](https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Einladen mso.dll Reverse Engineering","url":"https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh"},"datePublished":"2024-05-09T14:22:52.530Z","dateModified":"2024-05-09T14:22:50.785Z","description":"This post explores the Einladen Sherlock malware and the analysis of the dropped DLLs, including msoev.exe and mso.dll. It covers the purpose of msoev.exe, the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/46bc771d4384f7d4602790fe8ef09afe?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/46bc771d4384f7d4602790fe8ef09afe?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"0xdf hacks stuff","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"0xdf hacks stuff","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/16cdada70d5f4fac8b588c53bcf005ff","url":"https://daily.dev/sources/0xdf"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/einladen-mso-dll-reverse-engineering-u4xduqqgh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"microsoft,malware,reverse-engineering","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"0xdf hacks stuff","item":"https://daily.dev/sources/0xdf"},{"@type":"ListItem","position":3,"name":"Einladen mso.dll Reverse Engineering"}]}
```

