├── AsyncRAT_config_extractor.py ├── DcRat_config_extract.py ├── DynamicRAT_config_decrypt.py ├── ISFB_DecryptBSS.py ├── ISFB_URSNIF_config_extract.py ├── IcedID_decrypt.py ├── LummaC2 ├── LummaDecryptor.sln ├── LummaDecryptor │ ├── LummaDecryptor.vcxproj │ ├── LummaDecryptor.vcxproj.filters │ ├── LummaDecryptor.vcxproj.user │ └── LummaExtractor.cpp └── README.md ├── README.md ├── aurora_config_extractor.py ├── config_extract_QuasarRAT.py ├── config_extract_QuasarRAT_2.py ├── darkgate_config_extractor.py ├── darkvnc_config_extract.py ├── icedid_first_stage_decrypt.py ├── lumma_config_extract.py ├── meduza_stealer_config_extractor.py ├── metastealer_config_extractor.py ├── metastealer_string_decryptor.py ├── poseidon_config_extractor.py ├── raccoonstealerv2_c2_mutex_extract.py ├── remcos_config_extract.py ├── solarmarker_payload_extractor.py ├── stealc_decrypt_standalone.py ├── vidar_config_extractor.py ├── whitesnake_config_extractor_rc4_obfuscated.py ├── whitesnake_config_extractor_xor_obfuscated.py └── xtea_decrypt.py /AsyncRAT_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/AsyncRAT_config_extractor.py -------------------------------------------------------------------------------- /DcRat_config_extract.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/DcRat_config_extract.py -------------------------------------------------------------------------------- /DynamicRAT_config_decrypt.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/DynamicRAT_config_decrypt.py -------------------------------------------------------------------------------- /ISFB_DecryptBSS.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/ISFB_DecryptBSS.py -------------------------------------------------------------------------------- /ISFB_URSNIF_config_extract.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/ISFB_URSNIF_config_extract.py -------------------------------------------------------------------------------- /IcedID_decrypt.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/IcedID_decrypt.py -------------------------------------------------------------------------------- /LummaC2/LummaDecryptor.sln: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/LummaC2/LummaDecryptor.sln -------------------------------------------------------------------------------- /LummaC2/LummaDecryptor/LummaDecryptor.vcxproj: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/LummaC2/LummaDecryptor/LummaDecryptor.vcxproj -------------------------------------------------------------------------------- /LummaC2/LummaDecryptor/LummaDecryptor.vcxproj.filters: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/LummaC2/LummaDecryptor/LummaDecryptor.vcxproj.filters -------------------------------------------------------------------------------- /LummaC2/LummaDecryptor/LummaDecryptor.vcxproj.user: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/LummaC2/LummaDecryptor/LummaDecryptor.vcxproj.user -------------------------------------------------------------------------------- /LummaC2/LummaDecryptor/LummaExtractor.cpp: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/LummaC2/LummaDecryptor/LummaExtractor.cpp -------------------------------------------------------------------------------- /LummaC2/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/LummaC2/README.md -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/README.md -------------------------------------------------------------------------------- /aurora_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/aurora_config_extractor.py -------------------------------------------------------------------------------- /config_extract_QuasarRAT.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/config_extract_QuasarRAT.py -------------------------------------------------------------------------------- /config_extract_QuasarRAT_2.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/config_extract_QuasarRAT_2.py -------------------------------------------------------------------------------- /darkgate_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/darkgate_config_extractor.py -------------------------------------------------------------------------------- /darkvnc_config_extract.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/darkvnc_config_extract.py -------------------------------------------------------------------------------- /icedid_first_stage_decrypt.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/icedid_first_stage_decrypt.py -------------------------------------------------------------------------------- /lumma_config_extract.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/lumma_config_extract.py -------------------------------------------------------------------------------- /meduza_stealer_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/meduza_stealer_config_extractor.py -------------------------------------------------------------------------------- /metastealer_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/metastealer_config_extractor.py -------------------------------------------------------------------------------- /metastealer_string_decryptor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/metastealer_string_decryptor.py -------------------------------------------------------------------------------- /poseidon_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/poseidon_config_extractor.py -------------------------------------------------------------------------------- /raccoonstealerv2_c2_mutex_extract.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/raccoonstealerv2_c2_mutex_extract.py -------------------------------------------------------------------------------- /remcos_config_extract.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/remcos_config_extract.py -------------------------------------------------------------------------------- /solarmarker_payload_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/solarmarker_payload_extractor.py -------------------------------------------------------------------------------- /stealc_decrypt_standalone.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/stealc_decrypt_standalone.py -------------------------------------------------------------------------------- /vidar_config_extractor.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/vidar_config_extractor.py -------------------------------------------------------------------------------- /whitesnake_config_extractor_rc4_obfuscated.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/whitesnake_config_extractor_rc4_obfuscated.py -------------------------------------------------------------------------------- /whitesnake_config_extractor_xor_obfuscated.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/whitesnake_config_extractor_xor_obfuscated.py -------------------------------------------------------------------------------- /xtea_decrypt.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/RussianPanda95/Configuration_extractors/HEAD/xtea_decrypt.py --------------------------------------------------------------------------------