Forum Discussion

Phoenix123's avatar
Phoenix123
Icon for Bronze I rankBronze I
29 days ago

Brute Ratel: Extracting Indicators of Compromise

Hi Team, 

Please assist me with "Brute Ratel: Extracting Indicators of Compromise" Lab, I am stuck with Q. 4 and 7.

Thank you!

4 Replies

  • 7. Look at sample2.exe. What IP address can be found in the configuration section?

    4. What sequence of hexadecimal characters is used to separate sections of the configuration block? (\xDE\xAD\xBE)

    • netcat's avatar
      netcat
      Icon for Silver III rankSilver III

      We can't give you the solution, but if you tell what you did you'll get hints to point you to the right direction.

  • I got 4th answer.

    I just need hint to get the 7th, I tried reviewing sample2.exe using  Ghex hex editor.

  • Did you identify and decode the configuration section?