Giter Site home page Giter Site logo

aa-tools's Introduction

aa-tools

Artifact analysis tools by JPCERT/CC Analysis Center

Deob_NOOPLDR.py

IDA plugin Tool to deobfuscate CFF used by NOOPLDR malware

Article/Blog entry:
https://blogs.jpcert.or.jp/ja/2024/07/mirrorface.html (Japanese)

GobRAT-Analysis

C2 Commands Emulation tools in go language that supports analysis of GobRAT malware

Article/Blog entry:
https://blogs.jpcert.or.jp/ja/2023/05/gobrat.html (Japanese)
https://blogs.jpcert.or.jp/en/2023/05/gobrat.html (English)

apt17scan.py

Volatility plugin for detecting APT17 related malware and extracting its config

Article/Blog entry:
http://www.jpcert.or.jp/magazine/acreport-aptscan.html (Japanese)
http://blog.jpcert.or.jp/2015/11/a-volatility-plugin-created-for-detecting-malware-used-in-targeted-attacks.html (English)

emdivi_postdata_decoder.py

Python script for decoding Emdivi's post data

Article/Blog entry:
http://www.jpcert.or.jp/magazine/acreport-emdivi.html (Japanese)
http://blog.jpcert.or.jp/2015/11/decrypting-strings-in-emdivi.html (English)

emdivi_string_decryptor.py

IDAPython script for decrypting strings inside Emdivi

Article/Blog entry:
http://www.jpcert.or.jp/magazine/acreport-emdivi.html (Japanese)
http://blog.jpcert.or.jp/2015/11/decrypting-strings-in-emdivi.html (English)

Citadel Decryptor

Data decryption tool for Citadel

Article/Blog entry:
http://www.jpcert.or.jp/magazine/acreport-citadel.html (Japanese)
http://blog.jpcert.or.jp/2016/02/banking-trojan--27d6.html (English)

adwind_string_decoder.py

Python script for decoding strings inside Adwind

Article/Blog entry:
https://www.jpcert.or.jp/magazine/acreport-adwind.html (Japanese)
http://blog.jpcert.or.jp/2016/05/decoding-obfuscated-strings-in-adwind.html (English)

redleavesscan.py

Volatility plugin for detecting RedLeaves and extracting its config

Article/Blog entry:
https://www.jpcert.or.jp/magazine/acreport-redleaves2.html (Japanese)
http://blog.jpcert.or.jp/2017/05/volatility-plugin-for-detecting-redleaves-malware.html (English)

datper-splunk.py

Python script for detects Datper communication and adds result field to Splunk index

Article/Blog entry:
https://www.jpcert.or.jp/magazine/acreport-search-datper.html (Japanese)
http://blog.jpcert.or.jp/2017/09/chase-up-datper-bba7.html (English)

datper-elk.py

Python script for detects Datper communication and adds result field to Elasticsearch index

Article/Blog entry:
https://www.jpcert.or.jp/magazine/acreport-search-datper.html (Japanese)
http://blog.jpcert.or.jp/2017/09/chase-up-datper-bba7.html (English)

tscookie_decode.py

Python script for decrypting and parsing TSCookie configure data

Article/Blog entry:
https://www.jpcert.or.jp/magazine/acreport-tscookie.html (Japanese)
http://blog.jpcert.or.jp/2018/03/malware-tscooki-7aa0.html (English)

wellmess_cookie_decode.py

Python script for decoding WellMess's cookie data (support Python2)

Article/Blog entry:
https://blogs.jpcert.or.jp/ja/2018/06/wellmess.html (Japanese)
https://blogs.jpcert.or.jp/en/2018/07/malware-wellmes-9b78.html (English)

cobaltstrikescan.py

Volatility plugin for detecting Cobalt Strike Beacon and extracting its config

Article/Blog entry:
https://www.jpcert.or.jp/magazine/acreport-cobaltstrike.html (Japanese)
https://blog.jpcert.or.jp/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html (English)

tscookie_data_decode.py

Python script for decrypting and parsing TSCookie configure data

Article/Blog entry:
https://blogs.jpcert.or.jp/ja/2019/09/tscookie_loader.html (Japanese)
https://blogs.jpcert.or.jp/en/2019/09/tscookie-loader.html (English)

aa-tools's People

Contributors

0xebfehat avatar cakeoomoo avatar doomedraven avatar endo-t avatar inndy avatar kn1immt avatar rafiot avatar s03d4-164 avatar shu-tom avatar t-tani avatar tcgi avatar you0708 avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

aa-tools's Issues

Installation improvements

Hello,

I'd like to be able to install pyimpfuzzy via pip.
Obvious option would be to put the package on pypi.python.org or move the folder one level down so one can use perhaps:

pip install -e git+https://github.com/JPCERTCC/aa-tools.git#egg=pyimpfuzzy

Thanks in advance

Work on 2.6.1 and windows 10?

This is really cool! I just had a question...

Does this plugin work with 2.6.1 and Windows 10? I'm working with the new version from here -
https://github.com/fireeye/win10_volatility
but getting errors
Name PID Data VA


No suitable address space mapping found
Tried to open image as:
MachOAddressSpace: mac: need base
LimeAddressSpace: lime: need base
WindowsHiberFileSpace32: No base Address Space
WindowsCrashDumpSpace64BitMap: No base Address Space
HPAKAddressSpace: No base Address Space
VMWareAddressSpace: No base Address Space
QemuCoreDumpElf: No base Address Space
WindowsCrashDumpSpace32: No base Address Space
WindowsCrashDumpSpace64: No base Address Space
VMWareMetaAddressSpace: No base Address Space
VirtualBoxCoreDumpElf64: No base Address Space
Win10CompressedAMD64PagedMemory: No base Address Space
Win10CompressedIA32PagedMemoryPae: No base Address Space
SkipDuplicatesAMD64PagedMemory: No base Address Space
WindowsAMD64PagedMemory: No base Address Space
LinuxAMD64PagedMemory: No base Address Space
Win10CompressedIA32PagedMemory: No base Address Space
AMD64PagedMemory: No base Address Space
IA32PagedMemoryPae: No base Address Space

apt17scan & hikitconfig errors: "too many values to unpack"

Team,

I'm getting an error with both apt17scan and hikitconfig with both 2.4 and 2.5 versions of Volatility. Please let me know if I can provide more detail/testing.

Full error:

Traceback (most recent call last):
File "/vol-2.5_clean/vol.py", line 192, in
main()
File "/vol-2.5_clean/vol.py", line 183, in main
command.execute()
File "/vol-2.5_clean/volatility/commands.py", line 145, in execute
func(outfd, data)
File "/vol-2.5_clean/volatility/plugins/apt17scan.py", line 156, in render_text
for task, start, malname in data:
ValueError: too many values to unpack

pip2.7 install fails...

Your tool is referenced in CRITs services, but cannot be installed via PIP:

pip2.7 install git+https://github.com/JPCERTCC/aa-tools.git

Collecting git+https://github.com/JPCERTCC/aa-tools.git
Cloning https://github.com/JPCERTCC/aa-tools.git to ./pip-R87bsF-build
Unpacking objects: 100% (78/78), done.
Complete output from command python setup.py egg_info:
Traceback (most recent call last):
File "", line 1, in
IOError: [Errno 2] No such file or directory: '/tmp/pip-R87bsF-build/setup.py'

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.