PluginBench
Skill
Review
Audit score 70

ctf-malware

ljagiello/ctf-skills

Malware analysis and C2 traffic techniques for CTF challenges.

What is ctf-malware?

Reference skill for analyzing obfuscated scripts, malicious binaries, encrypted communications, and anti-analysis techniques in CTF contexts. Use when reversing malware samples, decoding C2 protocols, extracting configurations, or detecting evasion methods.

  • Analyze obfuscated scripts (JavaScript, PowerShell, bash) and deobfuscate eval/base64/hex payloads
  • Perform static and dynamic PE/.NET binary analysis with peframe, dnSpy, and AsmResolver
  • Decrypt custom crypto protocols (RC4, AES-CBC, ChaCha20) and identify encryption algorithms by byte signatures
  • Extract C2 traffic patterns from PCAP files and decode custom protocol beacons
  • Detect anti-analysis techniques (VM detection, API hashing, process injection, timing evasion)
  • Perform memory forensics with Volatility 3 (malfind, process injection detection) and shellcode analysis with Capstone/Unicorn

How to install ctf-malware

npx skills add https://github.com/ljagiello/ctf-skills --skill ctf-malware
Prerequisites
  • Python 3 with yara-python, pefile, capstone, oletools, unicorn, pycryptodome, volatility3, dissect.cobaltstrike
  • Linux: strace, ltrace, tshark, binwalk, binutils; macOS: Homebrew wireshark, binwalk, binutils, ghidra
  • dnSpy (manual install) for .NET decompilation on Windows
Claude Code
Cursor
Windsurf
Cline

How to use ctf-malware

  1. 1.Install Python packages and platform-specific tools per Prerequisites section
  2. 2.Use file/strings/xxd for initial static analysis of suspicious samples
  3. 3.Run peframe or pe-sieve for PE triage; dnSpy for .NET decompilation
  4. 4.Extract network indicators with strings grep and analyze PCAP with tshark
  5. 5.Identify encryption by byte signatures (AES S-box 0x637c777b, ChaCha20 'expand 32-byte k', RC4 S-box init)
  6. 6.Write and compile YARA rules with yarac to scan files or memory dumps for malware patterns
  7. 7.Use Volatility 3 malfind on memory dumps to detect injected code and process injection
  8. 8.Emulate shellcode safely with Unicorn Engine, hooking syscalls to avoid execution

Use cases

Good for
  • Reverse a trojanized plugin by diffing against official release and decoding custom alphabet C2 domains
  • Decrypt RC4-encrypted WebSocket C2 traffic by extracting keys from binary and remapping PCAP
  • Unpack PyInstaller+PyArmor samples and extract hardcoded malware configurations from .data sections
  • Write YARA rules to detect XOR loops and encoded payloads across file samples or memory dumps
  • Analyze Debian package postinst scripts for injected malicious code
Who it's for
  • CTF competitors analyzing malware and network challenges
  • Security researchers performing sandbox-safe malware triage
  • Reverse engineers extracting indicators of compromise and C2 infrastructure

ctf-malware FAQ

When should I use ctf-malware vs. ctf-reverse or ctf-forensics?

Use ctf-malware for samples with malware behavior, C2 traffic, or obfuscation. Switch to ctf-reverse for normal crackmes or packed binaries without malware traits; switch to ctf-forensics for disk carving or host artifacts.

How do I decrypt RC4 or AES-encrypted C2 traffic?

For RC4: extract the key from the binary, remap the PCAP port with tcprewrite, and add RSA/TLS keys. For AES-CBC: the key is typically MD5/SHA256 of a hardcoded string, and the IV is the first 16 bytes of ciphertext.

How do I identify which encryption algorithm is used?

Search for byte signatures: AES uses S-box 0x637c777b, ChaCha20 contains 'expand 32-byte k', TEA/XTEA use 0x9E3779B9, and RC4 has sequential S-box initialization.

What is the fastest way to triage a PE binary?

Run `peframe malware.exe` for quick static analysis, then `pe-sieve` for runtime analysis. Use `strings` to extract IPs/domains and check for known malware signatures with YARA rules.

How do I detect process injection or anti-analysis techniques?

Use Volatility 3 `windows.malfind` to detect PAGE_EXECUTE_READWRITE regions without mapped files. Look for VM detection (CPUID, MAC prefix, registry checks), API hashing (ROR13/DJB2/CRC32), and timing evasion (sleep/RDTSC checks).

Full instructions (SKILL.md)

Source of truth, from ljagiello/ctf-skills.


name: ctf-malware description: Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis, memory forensics for malware (Volatility malfind, process injection detection), anti-analysis techniques (VM/sandbox detection, timing evasion, API hashing, process injection, environment checks), or extracting malware configurations and indicators of compromise. license: MIT compatibility: Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation. allowed-tools: Bash Read Write Edit Glob Grep Task WebFetch WebSearch metadata: user-invocable: "false"

CTF Malware & Network Analysis

Quick reference for malware analysis CTF challenges. Each technique has a one-liner here; see supporting files for full details with code.

Prerequisites

Python packages (all platforms):

pip install yara-python pefile capstone oletools unicorn pycryptodome \
  volatility3 dissect.cobaltstrike

Linux (apt):

apt install strace ltrace tshark binwalk binutils

macOS (Homebrew):

brew install wireshark binwalk binutils ghidra

Manual install:

  • dnSpy — GitHub, .NET decompiler (Windows)

Additional Resources

  • scripts-and-obfuscation.md - JavaScript deobfuscation, PowerShell analysis, eval/base64 decoding, junk code detection, hex payloads, Debian package analysis, dynamic analysis techniques (strace/ltrace, network monitoring, memory string extraction, automated sandbox execution), YARA rules for malware detection, shellcode analysis (Unicorn Engine, Capstone), memory forensics for malware (Volatility 3 malfind, process injection detection), anti-analysis techniques (VM detection, timing evasion, API hashing, process injection), trojanized plugin analysis with custom alphabet C2 decoding
  • c2-and-protocols.md - C2 traffic patterns, custom crypto protocols, RC4 WebSocket, DNS-based C2, network indicators, PCAP analysis, AES-CBC, encryption ID, Telegram bot recovery, Poison Ivy RAT Camellia decryption
  • pe-and-dotnet.md - PE analysis (peframe, pe-sieve, pestudio), .NET analysis (dnSpy, AsmResolver), LimeRAT extraction, sandbox evasion, malware config extraction, PyInstaller+PyArmor

When to Pivot

  • If the sample is really just a normal crackme, packed challenge binary, or custom VM with no malware behavior, switch to /ctf-reverse.
  • If the main job is network reconstruction, disk carving, or host artifact recovery, switch to /ctf-forensics.
  • If the challenge turns into public attribution or infrastructure tracing, switch to /ctf-osint.

Quick Start Commands

# Static analysis
file suspicious_file
strings -n 8 suspicious_file | head -50
xxd suspicious_file | head -20

# PE analysis
python3 -c "import pefile; pe=pefile.PE('mal.exe'); print(pe.dump_info())" | head
peframe mal.exe

# Dynamic analysis (sandboxed!)
strace -f -s 200 ./suspicious 2>&1 | head -100
ltrace ./suspicious 2>&1 | head -50

# Network indicators
strings suspicious_file | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
strings suspicious_file | grep -iE 'http|ftp|ws://'

# YARA scan
yara -r rules.yar suspicious_file

Obfuscated Scripts

  • Replace eval/bash with echo to print underlying code; extract base64/hex blobs and analyze with file. See scripts-and-obfuscation.md.

JavaScript & PowerShell Deobfuscation

  • JS: Replace eval with console.log, decode unescape(), atob(), String.fromCharCode().
  • PowerShell: Decode -enc base64, replace IEX with output. See scripts-and-obfuscation.md.

Junk Code Detection

  • NOP sleds, push/pop pairs, dead writes, unconditional jumps to next instruction. Filter to extract real call targets. See scripts-and-obfuscation.md.

PCAP & Network Analysis

tshark -r file.pcap -Y "tcp.stream eq X" -T fields -e tcp.payload

Look for C2 on unusual ports. Extract IPs/domains with strings | grep. See c2-and-protocols.md.

Custom Crypto Protocols

  • Stream ciphers share keystream state for both directions; concatenate ALL payloads chronologically.
  • ChaCha20 keystream extraction: send nullbytes (0 XOR anything = anything). See c2-and-protocols.md.

C2 Traffic Patterns

  • Beaconing, DGA, DNS tunneling, HTTP(S) with custom headers, encoded payloads. See c2-and-protocols.md.

RC4-Encrypted WebSocket C2

  • Remap port with tcprewrite, add RSA key for TLS decryption, find RC4 key in binary. See c2-and-protocols.md.

Identifying Encryption Algorithms

  • AES: 0x637c777b S-box; ChaCha20: expand 32-byte k; TEA/XTEA: 0x9E3779B9; RC4: sequential S-box init. See c2-and-protocols.md.

AES-CBC in Malware

  • Key = MD5/SHA256 of hardcoded string; IV = first 16 bytes of ciphertext. See c2-and-protocols.md.

PE Analysis

peframe malware.exe      # Quick triage
pe-sieve                 # Runtime analysis
pestudio                 # Static analysis (Windows)

See pe-and-dotnet.md.

.NET Malware Analysis

  • Use dnSpy/ILSpy for decompilation; AsmResolver for programmatic analysis. LimeRAT C2: AES-256-ECB with MD5-derived key. See pe-and-dotnet.md.

Malware Configuration Extraction

  • Check .data section, PE/.NET resources, registry keys, encrypted config files. See pe-and-dotnet.md.

Sandbox Evasion Checks

  • VM detection, debugger detection, timing checks, environment checks, analysis tool detection. See pe-and-dotnet.md.

Anti-Analysis Techniques

VM detection (CPUID, MAC prefix, registry, disk size), timing evasion (sleep/RDTSC sandbox detection), API hashing (ROR13/DJB2/CRC32 + hashdb lookup), process injection (hollowing, APC, CreateRemoteThread), environment checks. See scripts-and-obfuscation.md.

Trojanized Plugin Analysis

Diff malicious plugin against official release to find injected code in try/except blocks. Custom alphabet rotation (C[(C.index(ch) - offset) % len(C)]) decodes C2 domain, XOR decodes endpoint path. See scripts-and-obfuscation.md.

PyInstaller + PyArmor Unpacking

  • pyinstxtractor.py to extract, PyArmor-Unpacker for protected code. See pe-and-dotnet.md.

Telegram Bot Evidence Recovery

  • Use bot token from malware source to call getUpdates and getFile APIs. See c2-and-protocols.md.

Debian Package Analysis

ar -x package.deb && tar -xf control.tar.xz  # Check postinst scripts

See scripts-and-obfuscation.md.

YARA Rules for Malware Detection

Write YARA rules to match byte patterns, strings, and regex against files or memory dumps. Detect XOR loops ({31 ?? 80 ?? ?? 4? 75}), base64 blobs, encoded PowerShell. Use yarac to compile for faster scanning. See scripts-and-obfuscation.md.

Shellcode Analysis

Disassemble with objdump -b binary -m i386:x86-64, emulate with Unicorn Engine (hook syscalls safely), or use Capstone for programmatic disassembly. Look for XOR decoder stubs. See scripts-and-obfuscation.md.

Memory Forensics for Malware

vol windows.malfind detects injected code (PAGE_EXECUTE_READWRITE without mapped file). windows.pstree reveals suspicious parent-child relationships. YARA scan memory with windows.vadyarascan.VadYaraScan. See scripts-and-obfuscation.md.

Network Indicators Quick Reference

strings malware | grep -E '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
tshark -r capture.pcap -Y "dns.qry.name" -T fields -e dns.qry.name | sort -u