
ELEGANTBOUNCER ist ein Erkennungstool für dateibasierte Exploits auf Mobilgeräten.

ELEGANTBOUNCER ist ein Tool zur Erkennung dateibasierter mobiler Exploits.
Es nutzt einen innovativen Ansatz zur erweiterten Identifizierung dateibasierter Bedrohungen, der keine In-the-Wild-Samples erfordert und herkömmliche Methoden auf Basis regulärer Ausdrücke oder IOCs übertrifft. Derzeit zielt es in erster Linie auf die Identifizierung mobiler Schwachstellen wie FORCEDENTRY (CVE-2021-30860), BLASTPASS (CVE-2023-4863, CVE-2023-41064) und TRIANGULATION (CVE-2023-41990) ab.
| Bedrohungsname | CVEs | Unterstützt |
|---|---|---|
| FORCEDENTRY | CVE-2021-30860 | ✅ |
| BLASTPASS | CVE-2023-4863, CVE-2023-41064 | ✅ |
| TRIANGULATION | CVE-2023-41990 | ✅ |
| CVE-2025-43300 | CVE-2025-43300 | ✅ |


Der TUI-Modus bietet eine Echtzeit-Visualisierung paralleler Scanvorgänge und zeigt alle aktiven Worker-Threads gleichzeitig an. Aktivieren Sie ihn beim Scannen von Verzeichnissen mit dem Flag --tui.
elegant-bouncer v0.2
ELEGANTBOUNCER Detection Tool
Detection tool for file-based mobile exploits.
A utility designed to detect the presence of known mobile APTs in commonly distributed files.
Usage: elegant-bouncer [OPTIONS] <Input path>
Arguments:
<Input path>
Path to the input file or folder
Options:
-v, --verbose
Print extra output while parsing
-s, --scan
Assess a given file or folder, checking for known vulnerabilities
-c, --create-forcedentry
Create a FORCEDENTRY-like PDF
-r, --recursive
Recursively scan subfolders
-m, --messaging
Scan messaging app databases for attachments (iOS backup format)
--ios-extract
Extract/reconstruct iOS backup to readable folder structure
-o, --output <OUTPUT>
Output directory for iOS backup extraction
-f, --force
Force overwrite of output directory if not empty
-e, --extensions <EXTENSIONS>
File extensions to scan (comma-separated, e.g., "pdf,webp,ttf")
Default: pdf,gif,webp,jpg,jpeg,png,tif,tiff,dng,ttf,otf
-h, --help
Print help information (use `-h` for a summary)
-V, --version
Print version information
Verwenden Sie --scan, um eine einzelne Datei auf bekannte Schwachstellen zu überprüfen:
elegantbouncer --scan suspicious_file.pdf
Scannen Sie alle unterstützten Dateien in einem Verzeichnis:
elegantbouncer --scan /path/to/folder
Verwenden Sie das Flag -r, um alle Unterverzeichnisse rekursiv zu scannen:
elegantbouncer --scan /path/to/folder -r
Geben Sie mit dem Flag -e an, welche Dateitypen gescannt werden sollen:
# Scan only PDF and DNG files
elegantbouncer --scan /path/to/folder -e pdf,dng
# Scan only image files recursively
elegantbouncer --scan /path/to/folder -r -e jpg,jpeg,png,webp,gif
Standardmäßig scannt das Tool Dateien mit diesen Erweiterungen:
Beim Scannen eines Verzeichnisses bietet das Tool:
[+] Scanning directory: /path/to/documents
[+] Recursive mode enabled
[+] Extensions: pdf, gif, webp, jpg, jpeg, png, tif, tiff, dng, ttf, otf
[1] Scanning: /path/to/documents/invoice.pdf
[2] Scanning: /path/to/documents/photo.jpg
[3] Scanning: /path/to/documents/malicious.webp
└─ THREAT found: BLASTPASS
[4] Scanning: /path/to/documents/report.pdf
└─ THREAT found: FORCEDENTRY
[+] Scanned 4 files
[+] Summary Results:
╭────────────────┬───────────────────────────────┬──────────────────────────────────────────────────────────────────────────┬──────────╮
│ name │ cve_ids │ description │ detected │
├────────────────┼───────────────────────────────┼──────────────────────────────────────────────────────────────────────────┼──────────┤
│ FORCEDENTRY │ CVE-2021-30860 │ Malicious JBIG2 PDF shared over iMessage │ Yes │
│ BLASTPASS │ CVE-2023-4863, CVE-2023-41064 │ Malicious WebP presumably shared over iMessage and other mediums │ Yes │
│ TRIANGULATION │ CVE-2023-41990 │ Maliciously crafted TrueType font embedded in PDFs shared over iMessage │ No │
│ CVE-2025-43300 │ CVE-2025-43300 │ Malicious DNG with JPEG Lossless compression exploiting RawCamera.bundle │ No │
╰────────────────┴───────────────────────────────┴──────────────────────────────────────────────────────────────────────────┴──────────╯
[!] Infected Files Details:
╭────────────────────────────────┬─────────────┬───────────────────────────────╮
│ path │ threat_name │ cve_ids │
├────────────────────────────────┼─────────────┼───────────────────────────────┤
│ /path/to/documents/report.pdf │ FORCEDENTRY │ CVE-2021-30860 │
│ /path/to/documents/malicious.webp │ BLASTPASS │ CVE-2023-4863, CVE-2023-41064 │
╰────────────────────────────────┴─────────────┴───────────────────────────────╯
Rekonstruieren Sie ein iOS-Backup in seine lesbare Ordnerstruktur:
# Extract backup to default location (creates _reconstructed folder)
elegantbouncer --ios-extract /path/to/ios/backup
# Extract to specific output directory
elegantbouncer --ios-extract /path/to/ios/backup -o /path/to/output
# Force overwrite if output directory exists
elegantbouncer --ios-extract /path/to/ios/backup -o /path/to/output --force
Scannen Sie iOS-Backups nach schädlichen Anhängen in Messaging-Apps:
# Scan messaging databases (iMessage, WhatsApp, Viber, Signal, Telegram)
elegantbouncer --scan --messaging /path/to/ios/backup
# Combine with extraction for complete analysis
elegantbouncer --ios-extract /path/to/ios/backup -o /tmp/extracted
elegantbouncer --scan --messaging /tmp/extracted
Diese Funktion erkennt Bedrohungen in Anhängen von:
Verwenden Sie --create-forcedentry, um eine PDF-Datei von Grund auf zu erstellen, die darauf ausgelegt ist, CVE-2021-30860 auszunutzen. In Arbeit.
Hinweis: Vorgefertigte Samples finden Sie im Verzeichnis samples/.
Verwenden Sie den Lockdown-Modus, um Ihre Angriffsfläche zu verringern, wenn Sie glauben, dass Sie eine Person von Interesse sind.