logo

Advent Of Configuration Extraction – Part 4: Turning capa Into A Configuration Extractor For TinyShell variant

ID: 360b3305-30c8-5f05-b144-6c9d4bad2d9d

STIX ID: report--360b3305-30c8-5f05-b144-6c9d4bad2d9d

Feed Name: Sekoia.io Blog

Threat Score
55/100

Date Published: 2025-12-22

Date Updated: 2026-04-29

Author: Pierre Le Bourhis, Jeremy Scion and Sekoia TDR

...
...

This report presents a technical walkthrough for extracting configuration data from a stripped Linux backdoor (TinySHell variant). It demonstrates using FLARE capa to locate an RC4 decryption routine, Capstone to reconstruct stack-based RC4 keys, LIEF to read encrypted blobs from the .rdata section, and malduck to decrypt the configuration, ultimately recovering C2 addresses and feature flags; the extractor code is published on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.