Files
Dobin Rutishauser f4a9057e06 initial version
2025-05-20 11:18:37 +02:00

14 lines
888 B
Markdown

## Bin2IP
A utility for translating a raw shellcode file into IPv4 or IPv6 addresses.
This script is based on Will Summerhill's IPv4Fuscation-Encrypted generation script. You can find the script [here](https://github.com/wsummerhill/IPv4Fuscation-Encrypted/blob/main/IPv4encrypt-shellcode.py).
The source code generated by this script is based in part on the [Orca000 HellShell project](https://gitlab.com/ORCA000/hellshell).
## Background
The Hive ransomware group was first observed storing shellcode as IP addresses in March of 2022. You can read SentinelOne's analysis of the technique [here](https://www.sentinelone.com/blog/hive-ransomware-deploys-novel-ipfuscation-technique/).
# References
[The Art of Obfuscation - Evading Static Malware Detection](https://infosecwriteups.com/the-art-of-obfuscation-evading-static-malware-detection-f4663ae4716f)
[Link to Red Siege blog]()