kaandemir993/PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis
Reverse engineering analysis of PureRAT, a multi-stage RAT that executes via msbuild.exe and communicates with C2 servers at pure8s.ddnsfree.com and 52.241.248.38. Uses .NET evasion techniques (DisableNativeImageLoad), file system manipulation (DeleteFile, WriteFile, ReadFile), and startup VBScript persistence.
GitHub repository with 16 stars and 2 forks.