Skip to content

hasherezade/funky_malware_formats

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

50 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

funky_malware_parsers

Build status

Parsers for custom malware formats ("Funky malware formats")

Contains:

  • lotus_parser: parser for Ocean Lotus custom executable format
  • isfb_parser: parser (and converter) for ISFB (Gozi v3) scrambled PE
  • bee_parser: parser for HiddenBee custom executable format - available here
  • iced_id_parser: parser (and converter) for IcedID scrambled PE