Imaginaryc2 - Tool Which Aims To Aid Inwards The Behavioral (Network) Analysis Of Malware
author: Felix Weyne ( website ) ( Twitter ) Imaginary C2 is a python tool which aims to assistance inward the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures HTTP requests towards selectively chosen domains/IPs. Additionally, the tool aims to larn inward slow to replay captured Command-and-Control responses/served payloads. By using this tool, an analyst tin feed the malware consistent network responses (e.g. C&C instructions for the malware to execute). Additionally, the analyst tin capture as well as inspect HTTP requests towards a domain/IP which is off-line at the fourth dimension of the analysis. Replay package captures Imaginary C2 provides 2 scripts to convert packet captures (PCAPs) or Fiddler Session Archives into request definitions which tin survive parsed yesteryear imaginary C2. Via these scripts the user tin extract HTTP asking URLs as well as domains, every bit good every bit HTTP responses. This way...