Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Emotet Config Parser - No IPs #61

Closed
Fother866 opened this issue Feb 13, 2020 · 2 comments
Closed

Emotet Config Parser - No IPs #61

Fother866 opened this issue Feb 13, 2020 · 2 comments

Comments

@Fother866
Copy link

Hi,

I'm not getting any ip addresses extracted from different emotet samples.
The rsa key gets extracted without problems.

I took the following example as a reference: https://cape.contextis.com/analysis/127913/

I'm running the lastest version (with the todays procdump fix - thx for that :) ).

Thx for attention!

@Fother866
Copy link
Author

I found the mistake.
My yara-python wasn't build with all necessary modules. :)

@doomedraven
Copy link
Collaborator

glad you solved that :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants