Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
BruteRatel-DetectionTools — Brute Ratel C4 badgers 디코딩을 위한 도구 및 규칙 모음 | Kitploit
도구/GitHubGitHub/immersive-labs-sec/bruteratel-detectiontools
Defensive ToolsMalware AnalysisCommand and ControlThreat IntelligenceIntrusion DetectionIncident Response
GitHubimmersive-labs-sec/bruteratel-detectiontools

BruteRatel-DetectionTools

Brute Ratel C4 badgers 디코딩을 위한 도구 및 규칙 모음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
67214년 전Kitploit 검토 완료

BruteRatel-DetectionTools

Brute Ratel C4 badger를 디코딩하기 위한 도구 및 규칙 모음

모든 도구와 규칙은 PaloAlto가 보고서 https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/ 에서 식별한 샘플을 기반으로 합니다.

Yara 규칙

이 Yara 규칙은 Unit42 보고서에 포함된 샘플과 이 규칙으로 추가로 식별된 샘플을 대상으로 테스트되었습니다.

root@kitploit:~
❯ yara rule.yar
BruteRatel ./hacker.exe
BruteRatel ./badger_x64.exe
BruteRatel ./trustwave.exe
BruteRatel ./adi_badger_x64_2.exe
BruteRatel ./npser.exe
BruteRatel ./twitter.exe
BruteRatel ./X64 Brute Ratel C4 Windows Kernel Module.bin
BruteRatel ./sample2.exe
BruteRatel ./HorionInjector.exe
BruteRatel ./http_badger_x64.exe
BruteRatel ./sample1.exe

구성 파서

Config 디코더는 Unit42 보고서에서 식별된 샘플과 위 Yara 규칙을 사용하여 찾은 추가 샘플을 대상으로 테스트되었습니다.

현재까지 샘플에서는 단 하나의 정적 키(static Key)만 관찰되었습니다.

root@kitploit:~
❯ python3 decoder.py sample1.exe                                                           
[+] Brute Ratel C4 Config Extractor by Immersive Labs
[+] Reading contents of file "sample1.exe"
  [-] Config Pattern Detected
  [-] May be encrypted testing key b'bYXJm/3#M?:XyMBF'
[+] Printing config to screen

||0|1|192.168.2.9|443|Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36|12345|P@ssw0rd|/admin||

도구 다운로드