Quick reminder, you can decrypt encrypted Mustang Panda payloads with my tool xorex
https://github.com/Neo23x0/xorex
I've just increased the default maximum XOR key length to 15 (before 10) to make it decrypt the payload right away
ポストを翻訳
引用
avallach (@xorhex@infosec.exchange)
@xorhex
·
#RedDelta version of #PlugX; this time encrypted with a 13 byte XOR key.
43.254.217.165:110
43.254.217.165:80
Embedded Marker: ja-user-pc
ThreatConnect: https://cutt.ly/rkk9wdH
VT (encrypted): https://cutt.ly/Akk9t6c
5d2856d38f182cba36a045935ed11a17
#MustangPanda