Skip to content
Notifications
Clear all

Guide: Getting the raw malware configs from the portal for analysis

4 Posts
4 Users
0 Reactions
15 Views
(@danielj)
Reputable Member
Joined: 3 months ago
Posts: 254
Topic starter   [#27792]

Hey everyone! I've been diving deep into the Mandiant Threat Intel portal lately, specifically trying to extract those raw malware configurations for some side analysis. While the portal's reports are fantastic, sometimes you just need the raw config to run your own parsers or feed into your internal tools.

I figured out a pretty reliable workflow and thought I'd share. It's not always obvious, and a couple of steps tripped me up at first.

**Here’s my step-by-step:**

* **Start with the Malware Family:** Navigate to the "Malware" section and find your target family (e.g., QakBot, IcedID). The key is to go to the "Samples" tab for that family.
* **Filter & Find:** Use the filters to narrow down samples. I often look for recent samples or those with a high "Malware Configuration" indicator count. Click into a specific sample detail view.
* **The Download Step:** In the sample details, look for the "Artifacts" section. If a config was extracted, you'll usually see a file named something like `config.json`, `config.bin`, or similar. **Here's the important part:** You might need to click the artifact's filename to preview it, and *then* the download button appears. It's a bit of a two-click process.
* **Alternative Route - Intel Collections:** Don't forget the "Collections" feature! If you've built a collection around a campaign, the extracted configs from related samples are often aggregated there for bulk download, which is a huge time-saver.

A couple of things to watch for:
* Format varies wildly—you might get JSON, encoded strings, or binary blobs. Be ready to decode.
* Not every sample has a config extracted, so sometimes it's a bit of hunt to find a good one.

This has been super helpful for building out our internal IOC databases and doing some custom enrichment. Has anyone else built a similar pipeline? I'd love to compare notes on how you're automating the ingestion or parsing these configs.

— Dan


spreadsheet ninja


   
Quote
(@ci_cd_crusader_v2)
Honorable Member
Joined: 5 months ago
Posts: 513
 

You're spot on about the download button hiding behind the preview. That UI choice feels like a puzzle designed to waste time. While I'm here for the analysis part, this whole dance reminds me why I prefer tools I can script against directly. If your workflow depends on clicking through a portal, you're one UI update away from it breaking.

Ever consider pulling this data via their API instead? Feels less fragile than relying on the whims of a web interface.


null


   
ReplyQuote
(@emilyh)
Estimable Member
Joined: 2 months ago
Posts: 166
 

The preview step is exactly where I got stuck too. I assumed clicking the filename would download it directly, so I kept missing the small download icon in the preview pane. It's not very intuitive. Does the API user441 mentioned provide these raw config artifacts directly, or is it more for metadata?



   
ReplyQuote
(@ethanp)
Reputable Member
Joined: 3 months ago
Posts: 371
 

That's a good clarification to seek. The API can indeed provide direct access to these config artifacts, but it requires a specific approach. You would typically retrieve the sample's details via the API first, which includes metadata and file hashes. The raw config file itself is often stored as a related artifact; you'd then use a secondary API call to download that specific artifact blob using its unique identifier from the initial response.

It is more programmatic, but it does bypass the UI's preview pane entirely. The trade-off is that you're working with the data structure as the platform defines it, rather than the human-oriented presentation layer.


Let's keep it constructive


   
ReplyQuote