ctf-malware
ljagiello/ctf-skills
Malware analysis and C2 traffic techniques for CTF challenges.
What is ctf-malware?
Reference skill for analyzing obfuscated scripts, malicious binaries, encrypted communications, and anti-analysis techniques in CTF contexts. Use when reversing malware samples, decoding C2 protocols, extracting configurations, or detecting evasion methods.
- Analyze obfuscated scripts (JavaScript, PowerShell, bash) and deobfuscate eval/base64/hex payloads
- Perform static and dynamic PE/.NET binary analysis with peframe, dnSpy, and AsmResolver
- Decrypt custom crypto protocols (RC4, AES-CBC, ChaCha20) and identify encryption algorithms by byte signatures
- Extract C2 traffic patterns from PCAP files and decode custom protocol beacons
- Detect anti-analysis techniques (VM detection, API hashing, process injection, timing evasion)
- Perform memory forensics with Volatility 3 (malfind, process injection detection) and shellcode analysis with Capstone/Unicorn
How to install ctf-malware
npx skills add https://github.com/ljagiello/ctf-skills --skill ctf-malware- Python 3 with yara-python, pefile, capstone, oletools, unicorn, pycryptodome, volatility3, dissect.cobaltstrike
- Linux: strace, ltrace, tshark, binwalk, binutils; macOS: Homebrew wireshark, binwalk, binutils, ghidra
- dnSpy (manual install) for .NET decompilation on Windows
How to use ctf-malware
- 1.Install Python packages and platform-specific tools per Prerequisites section
- 2.Use file/strings/xxd for initial static analysis of suspicious samples
- 3.Run peframe or pe-sieve for PE triage; dnSpy for .NET decompilation
- 4.Extract network indicators with strings grep and analyze PCAP with tshark
- 5.Identify encryption by byte signatures (AES S-box 0x637c777b, ChaCha20 'expand 32-byte k', RC4 S-box init)
- 6.Write and compile YARA rules with yarac to scan files or memory dumps for malware patterns
- 7.Use Volatility 3 malfind on memory dumps to detect injected code and process injection
- 8.Emulate shellcode safely with Unicorn Engine, hooking syscalls to avoid execution
Use cases
- Reverse a trojanized plugin by diffing against official release and decoding custom alphabet C2 domains
- Decrypt RC4-encrypted WebSocket C2 traffic by extracting keys from binary and remapping PCAP
- Unpack PyInstaller+PyArmor samples and extract hardcoded malware configurations from .data sections
- Write YARA rules to detect XOR loops and encoded payloads across file samples or memory dumps
- Analyze Debian package postinst scripts for injected malicious code
- CTF competitors analyzing malware and network challenges
- Security researchers performing sandbox-safe malware triage
- Reverse engineers extracting indicators of compromise and C2 infrastructure
ctf-malware FAQ
Use ctf-malware for samples with malware behavior, C2 traffic, or obfuscation. Switch to ctf-reverse for normal crackmes or packed binaries without malware traits; switch to ctf-forensics for disk carving or host artifacts.
For RC4: extract the key from the binary, remap the PCAP port with tcprewrite, and add RSA/TLS keys. For AES-CBC: the key is typically MD5/SHA256 of a hardcoded string, and the IV is the first 16 bytes of ciphertext.
Search for byte signatures: AES uses S-box 0x637c777b, ChaCha20 contains 'expand 32-byte k', TEA/XTEA use 0x9E3779B9, and RC4 has sequential S-box initialization.
Run `peframe malware.exe` for quick static analysis, then `pe-sieve` for runtime analysis. Use `strings` to extract IPs/domains and check for known malware signatures with YARA rules.
Use Volatility 3 `windows.malfind` to detect PAGE_EXECUTE_READWRITE regions without mapped files. Look for VM detection (CPUID, MAC prefix, registry checks), API hashing (ROR13/DJB2/CRC32), and timing evasion (sleep/RDTSC checks).
Full instructions (SKILL.md)
Source of truth, from ljagiello/ctf-skills.
name: ctf-malware description: Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility malfind, process injection detection), anti-analysis techniques (VM/sandbox detection, timing evasion, API hashing, process injection, environment checks), or extracting malware configurations and indicators of compromise. license: MIT compatibility: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation. allowed-tools: Bash Read Write Edit Glob Grep Task WebFetch WebSearch metadata: user-invocable: "false"
CTF Malware & Network Analysis
Quick reference for malware analysis CTF challenges. Each technique has a one-liner here; see supporting files for full details with code.
Prerequisites
Python packages (all platforms):
pip install yara-python pefile capstone oletools unicorn pycryptodome \
volatility3 dissect.cobaltstrike
Linux (apt):
apt install strace ltrace tshark binwalk binutils
macOS (Homebrew):
brew install wireshark binwalk binutils ghidra
Manual install:
- dnSpy — GitHub, .NET decompiler (Windows)
Additional Resources
- scripts-and-obfuscation.md - JavaScript deobfuscation, PowerShell analysis, eval/base64 decoding, junk code detection, hex payloads, Debian package analysis, dynamic analysis techniques (strace/ltrace, network monitoring, memory string extraction, automated sandbox execution), YARA rules for malware detection, shellcode analysis (Unicorn Engine, Capstone), memory forensics for malware (Volatility 3 malfind, process injection detection), anti-analysis techniques (VM detection, timing evasion, API hashing, process injection), trojanized plugin analysis with custom alphabet C2 decoding
- c2-and-protocols.md - C2 traffic patterns, custom crypto protocols, RC4 WebSocket, DNS-based C2, network indicators, PCAP analysis, AES-CBC, encryption ID, Telegram bot recovery, Poison Ivy RAT Camellia decryption
- pe-and-dotnet.md - PE analysis (peframe, pe-sieve, pestudio), .NET analysis (dnSpy, AsmResolver), LimeRAT extraction, sandbox evasion, malware config extraction, PyInstaller+PyArmor
When to Pivot
- If the sample is really just a normal crackme, packed challenge binary, or custom VM with no malware behavior, switch to
/ctf-reverse. - If the main job is network reconstruction, disk carving, or host artifact recovery, switch to
/ctf-forensics. - If the challenge turns into public attribution or infrastructure tracing, switch to
/ctf-osint.
Quick Start Commands
# Static analysis
file suspicious_file
strings -n 8 suspicious_file | head -50
xxd suspicious_file | head -20
# PE analysis
python3 -c "import pefile; pe=pefile.PE('mal.exe'); print(pe.dump_info())" | head
peframe mal.exe
# Dynamic analysis (sandboxed!)
strace -f -s 200 ./suspicious 2>&1 | head -100
ltrace ./suspicious 2>&1 | head -50
# Network indicators
strings suspicious_file | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
strings suspicious_file | grep -iE 'http|ftp|ws://'
# YARA scan
yara -r rules.yar suspicious_file
Obfuscated Scripts
- Replace
eval/bashwithechoto print underlying code; extract base64/hex blobs and analyze withfile. See scripts-and-obfuscation.md.
JavaScript & PowerShell Deobfuscation
- JS: Replace
evalwithconsole.log, decodeunescape(),atob(),String.fromCharCode(). - PowerShell: Decode
-encbase64, replaceIEXwith output. See scripts-and-obfuscation.md.
Junk Code Detection
- NOP sleds, push/pop pairs, dead writes, unconditional jumps to next instruction. Filter to extract real
calltargets. See scripts-and-obfuscation.md.
PCAP & Network Analysis
tshark -r file.pcap -Y "tcp.stream eq X" -T fields -e tcp.payload
Look for C2 on unusual ports. Extract IPs/domains with strings | grep. See c2-and-protocols.md.
Custom Crypto Protocols
- Stream ciphers share keystream state for both directions; concatenate ALL payloads chronologically.
- ChaCha20 keystream extraction: send nullbytes (0 XOR anything = anything). See c2-and-protocols.md.
C2 Traffic Patterns
- Beaconing, DGA, DNS tunneling, HTTP(S) with custom headers, encoded payloads. See c2-and-protocols.md.
RC4-Encrypted WebSocket C2
- Remap port with
tcprewrite, add RSA key for TLS decryption, find RC4 key in binary. See c2-and-protocols.md.
Identifying Encryption Algorithms
- AES:
0x637c777bS-box; ChaCha20:expand 32-byte k; TEA/XTEA:0x9E3779B9; RC4: sequential S-box init. See c2-and-protocols.md.
AES-CBC in Malware
- Key = MD5/SHA256 of hardcoded string; IV = first 16 bytes of ciphertext. See c2-and-protocols.md.
PE Analysis
peframe malware.exe # Quick triage
pe-sieve # Runtime analysis
pestudio # Static analysis (Windows)
See pe-and-dotnet.md.
.NET Malware Analysis
- Use dnSpy/ILSpy for decompilation; AsmResolver for programmatic analysis. LimeRAT C2: AES-256-ECB with MD5-derived key. See pe-and-dotnet.md.
Malware Configuration Extraction
- Check .data section, PE/.NET resources, registry keys, encrypted config files. See pe-and-dotnet.md.
Sandbox Evasion Checks
- VM detection, debugger detection, timing checks, environment checks, analysis tool detection. See pe-and-dotnet.md.
Anti-Analysis Techniques
VM detection (CPUID, MAC prefix, registry, disk size), timing evasion (sleep/RDTSC sandbox detection), API hashing (ROR13/DJB2/CRC32 + hashdb lookup), process injection (hollowing, APC, CreateRemoteThread), environment checks. See scripts-and-obfuscation.md.
Trojanized Plugin Analysis
Diff malicious plugin against official release to find injected code in try/except blocks. Custom alphabet rotation (C[(C.index(ch) - offset) % len(C)]) decodes C2 domain, XOR decodes endpoint path. See scripts-and-obfuscation.md.
PyInstaller + PyArmor Unpacking
pyinstxtractor.pyto extract, PyArmor-Unpacker for protected code. See pe-and-dotnet.md.
Telegram Bot Evidence Recovery
- Use bot token from malware source to call
getUpdatesandgetFileAPIs. See c2-and-protocols.md.
Debian Package Analysis
ar -x package.deb && tar -xf control.tar.xz # Check postinst scripts
See scripts-and-obfuscation.md.
YARA Rules for Malware Detection
Write YARA rules to match byte patterns, strings, and regex against files or memory dumps. Detect XOR loops ({31 ?? 80 ?? ?? 4? 75}), base64 blobs, encoded PowerShell. Use yarac to compile for faster scanning. See scripts-and-obfuscation.md.
Shellcode Analysis
Disassemble with objdump -b binary -m i386:x86-64, emulate with Unicorn Engine (hook syscalls safely), or use Capstone for programmatic disassembly. Look for XOR decoder stubs. See scripts-and-obfuscation.md.
Memory Forensics for Malware
vol windows.malfind detects injected code (PAGE_EXECUTE_READWRITE without mapped file). windows.pstree reveals suspicious parent-child relationships. YARA scan memory with windows.vadyarascan.VadYaraScan. See scripts-and-obfuscation.md.
Network Indicators Quick Reference
strings malware | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
tshark -r capture.pcap -Y "dns.qry.name" -T fields -e dns.qry.name | sort -u
Related skills
More from ljagiello/ctf-skills and the wider catalog.

ctf-misc
Miscellaneous CTF techniques for encoding, jails, RF/SDR, DNS, and cross-category puzzles.

ctf-osint
Open source intelligence techniques for CTF challenges: OSINT lookups, social media tracking, geolocation, DNS recon, and data identification.

ctf-pwn
Binary exploitation techniques for CTF challenges: buffer overflows, ROP, heap bugs, shellcode, and privilege escalation.

ctf-reverse
Reverse engineering techniques for CTF challenges: binaries, APKs, WASM, firmware, custom VMs, and anti-analysis logic.

ctf-web
Web exploitation techniques for CTF challenges: XSS, SQLi, SSTI, SSRF, XXE, JWT, auth bypass, and more.

ctf-writeup
Generate standardized CTF writeup documentation for competition submission and organizer review.