Malware samples, analysis exercises and other interesting resources.
-
Updated
Jan 13, 2024 - HTML
Malware samples, analysis exercises and other interesting resources.
A repository full of malware samples.
Control-flow-flattening and string deobfuscator
Collection of various files from infected hosts
Links to malware-related YARA rules
EmoKill is an Emotet process detection and killing tool for Windows OS. It avoids wasting time after detection of Emotet. Any process that matches the pattern of Emotet based on the logic of EmoCheck by JPCERT/CC will be detected by EmoKill and killed as soon as possible.
a State-Machine reversing exercise
Emotet Loader helps execute Emotet modules in isolation. Emotet is one of the most active botnets, that delivers its modules, such as credit card stealer or SMB spreader, to the user machines. Emotet Loader allows to run the modules separately from the core component and help analyzing their behavior.
Included domain list to PowerShell script...
Add a description, image, and links to the emotet topic page so that developers can more easily learn about it.
To associate your repository with the emotet topic, visit your repo's landing page and select "manage topics."