logo

NETWIRE Configuration Extractor

ID: 5d650374-b1d3-5d9d-b0c3-754d85704e64

STIX ID: report--5d650374-b1d3-5d9d-b0c3-754d85704e64

Feed Name: Elastic Security Labs

Date Published: 2023-01-27

Date Updated: 2026-04-27

...
...

This document provides setup and usage instructions for a tool that extracts configuration artifacts from NETWIRE malware samples, including encryption keys, C2 endpoints, and strings. It recommends Docker as the primary execution method (with an option to use Poetry locally), and supports processing single files or directories of unpacked samples, outputting the recovered data to a specified directory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.