pe-bear

Challenge 2 of Zero2Auto biweekly challenges

IcedID malware challenge This is a malware challenge related to the Zero2Automated course (number 2 out of currently 4). The aim for this challenge was to unpack this IcedID binary, figure out how the configuration was stored, and develop a script to automatically extract the config information. The malware bazaar link also lets us know that the following IOC exists: ilekvoyn[.]com Unpacking In this case the file is a DLL file containing a number of exports.