CAPEv2
CAPEv2 copied to clipboard
Malware Configuration And Payload Extraction
I don't know if this is a good pr. - Add a field to the database to display the real file name. - need `cd /opt/CAPEv2/utils/db_migration && alembic upgrade head`...
[GoLang_ServHelper.zip](https://github.com/kevoreilly/CAPEv2/files/7774340/GoLang_ServHelper.zip) The password is infected. The final payload should be ServHelper RAT. The dropper should load the .NET ServHelper dropper into memory to execute it.
## About accounts on [capesandbox.com](https://capesandbox.com/) * Issues isn't the way to ask for account acctivation. Ping capesandbox in [Twitter](https://twitter.com/capesandbox) with your username ## This is opensource and you getting __free__...
Again me :) Problematic block is [here](https://github.com/kevoreilly/CAPEv2/blob/master/modules/processing/network.py#L742-L775) So, TCP connections are recognized by first packet seen, where this can be a problem in lots of specific situations (TCP out of...
# Prerequisites Please answer the following questions for yourself before submitting an issue. - [x] I am running the latest version - [x] I checked the documentation and found no...
# Prerequisites Please answer the following questions for yourself before submitting an issue. - [X] I am running the latest version - [X] I checked the documentation and found no...
Is 7z in analyzer/windows/bin? if not os.path.exists(seven_zip_path): Let's hope it's in the VM image actors are using LNK files that use relative directory traversal at arbitrary depth. They expect to...
refurb
## About accounts on [capesandbox.com](https://capesandbox.com/) * Issues isn't the way to ask for account acctivation. Ping capesandbox in [Twitter](https://twitter.com/capesandbox) with your username ## This is opensource and you getting __free__...
## About accounts on [capesandbox.com](https://capesandbox.com/) * Issues isn't the way to ask for account acctivation. Ping capesandbox in [Twitter](https://twitter.com/capesandbox) with your username ## This is opensource and you getting __free__...