logo

Part 4: Extracting TinyShell Configs

ID: 293a90da-11db-5ac5-8448-5ead1c2c57db

STIX ID: report--293a90da-11db-5ac5-8448-5ead1c2c57db

Feed Name: Sekoia.com

Threat Score
65/100

Date Published: 2025-12-22

Date Updated: 2026-07-20

...
...

This report details a static-analysis pipeline to extract configuration from a lightweight, stripped Linux backdoor that hides C2 and flags using RC4 obfuscation. The extractor embeds a minimal set of FLARE capa rules to identify the RC4 PRGA routine, uses Capstone to reconstruct stack-built RC4 keys from caller instruction sequences, and leverages LIEF and malduck to enumerate and decrypt contiguous encrypted blobs (recovering C2:port and feature flags). The write-up includes code snippets and methodology for reliably locating and decrypting the backdoor's configuration in stripped binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.