You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have recently analysed a XWORM backdoor and rat_king_parser identified the family and decrypted the configuration. My sample was not difficult to analyse with dnSpy, but it was still nice to have the configuration extracted by rat_king_parser to double check. I think we should add a package for rat_king_parser. It can be easily installed using pip, so we can use VM-Install-With-Pip to install it.
@mandiant/flare-vm what do you think about adding it to the default configuration of FLARE-VM?
The text was updated successfully, but these errors were encountered:
Details
I have recently analysed a XWORM backdoor and rat_king_parser identified the family and decrypted the configuration. My sample was not difficult to analyse with dnSpy, but it was still nice to have the configuration extracted by rat_king_parser to double check. I think we should add a package for rat_king_parser. It can be easily installed using
pip
, so we can useVM-Install-With-Pip
to install it.@mandiant/flare-vm what do you think about adding it to the default configuration of FLARE-VM?
The text was updated successfully, but these errors were encountered: