Part 4: Extracting TinyShell Configs
ID: 293a90da-11db-5ac5-8448-5ead1c2c57db
STIX ID: report--293a90da-11db-5ac5-8448-5ead1c2c57db
Feed Name: Sekoia.com
This report details a static-analysis pipeline to extract configuration from a lightweight, stripped Linux backdoor that hides C2 and flags using RC4 obfuscation. The extractor embeds a minimal set of FLARE capa rules to identify the RC4 PRGA routine, uses Capstone to reconstruct stack-built RC4 keys from caller instruction sequences, and leverages LIEF and malduck to enumerate and decrypt contiguous encrypted blobs (recovering C2:port and feature flags). The write-up includes code snippets and methodology for reliably locating and decrypting the backdoor's configuration in stripped binaries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
