Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration

In the second part of our “Advent of Configuration Extraction” series, we unwrap QuasarRAT, a popular .NET remote access trojan (RAT), and show how to extract its encrypted configuration out of the binary. The article begins by detailing the environment: Jupyter Notebook, pythonnet, dnSpy and friends—so every step is reproducible. Next, it presents the construction […]

La publication suivante Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration est un article de Sekoia.io Blog.

This article has been indexed from Sekoia.io Blog

Read the original article: