kcreyts / plugxdecoderLinks
Decodes PlugX traffic and encrypted/compressed artifacts
☆38Updated 12 years ago
Alternatives and similar repositories for plugxdecoder
Users that are interested in plugxdecoder are comparing it to the libraries listed below
Sorting:
- ☆52Updated 10 years ago
- zer0m0n driver for cuckoo sandbox☆87Updated 9 years ago
- Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents☆23Updated 8 years ago
- Extract OLEv1 objects from RTF files by instrumenting Word☆51Updated 5 years ago
- Transfer EIP control to shellcode during malware analysis investigation☆75Updated 10 years ago
- Smart DLL execution for malware analysis in sandbox systems☆144Updated 10 years ago
- a modified version base on Tracecorn☆20Updated 5 years ago
- Telsy CTI Research Team☆57Updated 4 years ago
- POSHSPY backdoor code☆43Updated 8 years ago
- An exploit for CVE-2016-7255 on Windows 7/8/8.1/10(pre-anniversary) 64 bit☆81Updated 8 years ago
- ☆43Updated 6 years ago
- Analysis PE file or Shellcode☆49Updated 8 years ago
- Malware.lu configuration extractor☆25Updated 11 years ago
- Modified edition of cuckoomon☆49Updated 7 years ago
- Simple NTFS crawler.☆56Updated 7 years ago
- CAPE monitor DLLs☆41Updated 5 years ago
- ☆43Updated 6 years ago
- Linux malware analysis based on Cuckoo Sandbox.☆40Updated 2 years ago
- Modified edition of cuckoo community modules☆32Updated 5 years ago
- a program to detect reflective dll injection on a live machine☆74Updated 9 years ago
- Supporting Files on my analysis of the malware designated hdroot.☆59Updated 8 years ago
- A tool for de-obfuscating PowerShell scripts☆68Updated 6 years ago
- Pure Python parser for Application Compatibility Shim Databases (.sdb files)☆108Updated 4 years ago
- Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research☆53Updated 7 years ago
- An implementation of a generic unpacker based on Intel PIN☆28Updated 8 years ago
- ☆34Updated 7 years ago
- HackSys Extreme Vulnerable Driver - Windows 10 x64 StackOverflow Exploit with SMEP Bypass☆65Updated 7 years ago
- A tiny PoC to inject and execute code into explorer.exe with WM_SETTEXT+WM_COPYDATA+SetThreadContext☆50Updated 7 years ago
- Yet another Python library to read and write PE/PE+ files.☆78Updated 8 years ago
- Various Yara signatures (possibly to be included in a release later).☆86Updated 6 years ago