Forum Discussion

Phoenix123's avatar
Phoenix123
Bronze I
7 months ago

Brute Ratel: Extracting Indicators of Compromise

Hi Team, 

Please assist me with "Brute Ratel: Extracting Indicators of Compromise" Lab, I am stuck with Q. 4 and 7.

Thank you!

5 Replies

  • 7. Look at sample2.exe. What IP address can be found in the configuration section?

    4. What sequence of hexadecimal characters is used to separate sections of the configuration block? (\xDE\xAD\xBE)

    • netcat's avatar
      netcat
      Icon for Advocate rankAdvocate

      We can't give you the solution, but if you tell what you did you'll get hints to point you to the right direction.

  • I got 4th answer.

    I just need hint to get the 7th, I tried reviewing sample2.exe using  Ghex hex editor.

  • Did you identify and decode the configuration section?