NETWIRE Configuration Extractor
ID: 5d650374-b1d3-5d9d-b0c3-754d85704e64
STIX ID: report--5d650374-b1d3-5d9d-b0c3-754d85704e64
Feed Name: Elastic Security Labs
This document provides setup and usage instructions for a tool that extracts configuration artifacts from NETWIRE malware samples, including encryption keys, C2 endpoints, and strings. It recommends Docker as the primary execution method (with an option to use Poetry locally), and supports processing single files or directories of unpacked samples, outputting the recovered data to a specified directory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
