Advent Of Configuration Extraction – Part 4: Turning capa Into A Configuration Extractor For TinyShell variant
ID: 360b3305-30c8-5f05-b144-6c9d4bad2d9d
STIX ID: report--360b3305-30c8-5f05-b144-6c9d4bad2d9d
Feed Name: Sekoia.io Blog
Date Published: 2025-12-22
Date Updated: 2026-04-29
Author: Pierre Le Bourhis, Jeremy Scion and Sekoia TDR
This report presents a technical walkthrough for extracting configuration data from a stripped Linux backdoor (TinySHell variant). It demonstrates using FLARE capa to locate an RC4 decryption routine, Capstone to reconstruct stack-based RC4 keys, LIEF to read encrypted blobs from the .rdata section, and malduck to decrypt the configuration, ultimately recovering C2 addresses and feature flags; the extractor code is published on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
