This repository includes scripts that were obtained through in-depth reverse engineering of malware samples.
Currently, the following scripts are available:
- icedid_ida.py - decrypts strings in IDA
- icedid_config.py - decrypts and parses IcedID config