Advent of Configuration Extraction
ID: 64ef2044-49b3-5264-9326-2d165c4ee365
STIX ID: report--64ef2044-49b3-5264-9326-2d165c4ee365
Feed Name: Sekoia.com
Threat Score
This article introduces Sekoia TDR’s Assemblyline analysis pipeline and the ConfigExtractor service, demonstrating an automated workflow to extract Kaiji IoT botnet C2 configuration (Base64-encoded strings parsed into C2:Port tuples) using FLOSS, YARA, and the MACO schema; it also notes Kaiji’s capabilities (SSH brute-force, CVE-2024-7954 and CVE-2023-1389 exploitation, DDoS, reverse shells and mining) and how extracted indicators feed threat intelligence systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
