mandiant / mandiant/VM-Packages

Pre-Populated Crypto Wallet Data

Open
#1,430 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

:cyclone: FLARE-VM :gem: enhancement
Dominant language
PowerShell
Stars
246
Forks
98
Avg merge
9h 30m
Merged PRs (30d)
7

Description

Details

I would like to be creating this ticket with a lot more research into what data would be useful, but I'm about to have my hands full with other work and Ana suggested I create this ticket in the meantime.

Working on a Data Stealer recently, I thought it would be awesome if the FLARE-VM could come prepackaged with software/browser extensions and fake data that would allow data stealers to execute fully and make the results from dynamic analysis more fruitful.

The stealer I was looking at provided a wide list of wallet related files and extensions that it targeted. If I had more time, my first approach would be to try to install some of these tools targeted by the stealer, see if I create any files without having to actually buy crypto, and then run the malware to see if it actually successfully steals the data. From there, I'm thinking it would be somewhat trivial to create fake data. I'm not super familiar with the FLARE-VM installation process, but I'm thinking the next step would be packaging all of this into something that could be automatically installed.

Once I have more time, I plan on revisiting this sample and perhaps testing out some installation. Hopefully, then I can provide more useful information.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by researching which wallet files and browser extensions the stealer targets, then review the FLARE-VM installation and packaging process. Done would require a defined set of software and fake data that can be automatically installed and supports fuller dynamic analysis.

Written by the indexing model from the issue text.

Assessment

Domain
reverse-engineering, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.