![m4n0w4r on Twitter: "馃敟Maybe found a sample that related to #MustangPanda, custom #PlugX??. Load AvastDB.dat and decrypt to Dll. Then use EnumSystemCodePagesW (rarely seen) function to load lpCodePageEnumProc --> decrypted Dll. 馃懝Sample m4n0w4r on Twitter: "馃敟Maybe found a sample that related to #MustangPanda, custom #PlugX??. Load AvastDB.dat and decrypt to Dll. Then use EnumSystemCodePagesW (rarely seen) function to load lpCodePageEnumProc --> decrypted Dll. 馃懝Sample](https://pbs.twimg.com/media/FVxLK24agAEZ_QB.png:large)
m4n0w4r on Twitter: "馃敟Maybe found a sample that related to #MustangPanda, custom #PlugX??. Load AvastDB.dat and decrypt to Dll. Then use EnumSystemCodePagesW (rarely seen) function to load lpCodePageEnumProc --> decrypted Dll. 馃懝Sample
![Blue Team News on Twitter: "IcedID decrypter: A script to statically decrypt license.dat files associated with IcedID infections. The script will also decrypt the .data section from unpacked IcedID samples. https://t.co/JGWNsOPXqj #cyber # Blue Team News on Twitter: "IcedID decrypter: A script to statically decrypt license.dat files associated with IcedID infections. The script will also decrypt the .data section from unpacked IcedID samples. https://t.co/JGWNsOPXqj #cyber #](https://pbs.twimg.com/media/Fgk1U9BagAEm8jG.jpg)
Blue Team News on Twitter: "IcedID decrypter: A script to statically decrypt license.dat files associated with IcedID infections. The script will also decrypt the .data section from unpacked IcedID samples. https://t.co/JGWNsOPXqj #cyber #
![decryption - Extract text data from a encrypted .DAT file of a game - Reverse Engineering Stack Exchange decryption - Extract text data from a encrypted .DAT file of a game - Reverse Engineering Stack Exchange](https://i.stack.imgur.com/hzeOH.png)