BigHugger
sk Skill · meltedinhex

extracting-config-from-a-running-sample

Extracts an embedded malware configuration (C2 hosts, ports, campaign IDs, keys) from a process memory dump by locating decrypted config structures and decoding common obfuscation layers. Activates for requests to extract malware config from a memory dump, recover C2 settings from a running sample, or decode an in-memory configuration block.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythondynamic-analysisc2memoryconfig-extractionmalware-analysis
Host repository
meltedinhex/analyst-ai-pack
Version
1.0.0
Licence
Apache-2.0
Host stars
22
Host language
Python