Files
reverse-skill/CTF-Sandbox-Orchestrator/competition-malware-config/references/malware-config.md
T
2026-08-08 18:32:33 +08:00

1.2 KiB

Malware Config And Staging Checklist

Hunt For The Config Boundary

  • Resources, overlays, embedded archives, section anomalies, decode helpers, registry seeds, bootstrap responses, stage2 memory
  • Nearby markers: URLs, mutex seeds, wallet-like strings, campaign IDs, bot IDs, task routes, persistence names

Reconstruct The Transform Chain

Track in order:

  1. Container or embedded layer
  2. Compression or chunking
  3. Encoding or substitution
  4. XOR or custom masks
  5. Crypto
  6. Final parse into fields

Tie Fields To Behavior

  • Beacon path or host -> network flow
  • Mutex or install path -> persistence branch
  • Campaign or bot id -> server-side routing or tasking
  • Wallet or key material -> downstream protocol or decryption branch

Evidence To Keep

  • One compact block for offsets, hashes, decode helpers, keys, masks
  • One compact block for parsed fields and what branch each field affects
  • Original, unpacked, dumped, and parsed outputs kept as separate artifacts

Common Pitfalls

  • Treating one IOC-looking string as the config without proving the full chain
  • Mixing fields from separate decode paths as if they came from one blob
  • Forgetting to prove where config becomes plaintext