logo

Advent of Configuration Extraction

ID: 64ef2044-49b3-5264-9326-2d165c4ee365

STIX ID: report--64ef2044-49b3-5264-9326-2d165c4ee365

Feed Name: Sekoia.com

Threat Score
55/100

Date Published: 2025-12-01

Date Updated: 2026-07-20

...
...

This article introduces Sekoia TDR’s Assemblyline analysis pipeline and the ConfigExtractor service, demonstrating an automated workflow to extract Kaiji IoT botnet C2 configuration (Base64-encoded strings parsed into C2:Port tuples) using FLOSS, YARA, and the MACO schema; it also notes Kaiji’s capabilities (SSH brute-force, CVE-2024-7954 and CVE-2023-1389 exploitation, DDoS, reverse shells and mining) and how extracted indicators feed threat intelligence systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.