Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

+105
View File
@@ -0,0 +1,105 @@
# Data Encoding
Malware uses encoding for a variety of reasons, the main one is for encrypting network-based communication.
- Malware needs to hide its intent
- This applies to both its operation but also to the data it uses
- Data encoding refers to all forms of content modification used for the purpose of hiding intent
- Malware will use data encoding to:
- Hide configuration information
- Save information to a staging file before stealing it
- To store strings used by the malware
- Imagine a key logger, logs what the user is searching for. The file would come up
- Disguise itself as a legitimate tool
When analysing the goal is to first find the encryption functions and then using that to decode whatever information is encoded.
#### Mechanisms for data encoding
- Malware could (and does) use standard cryptographic algorithms for data encoding
- These algorithms have high entropy
- This can be seen in IDA
- Ransomware will use standard encryption as they want the data to not be decrypted
- But malware is just as likely to use simple techniques
- Are small enough to be used in space-constrained environments
- Less obvious than more complex ciphers
- Low overhead, little impact on performance
- Not expecting immunity from being cracked, rather simply looking for an easy way to prevent basic analysis.
#### XOR Cipher
- Common mechanism used by malware authors
- Convenient to use
- Simple to implement (one instruction)
- Reversible - same function can encode and decode
##### Brute Forcing xor encoding
- Very easy to brute force crack simple xor encoding
- Only one of 256 possible values used to encode data
- Simply take a portion of the encoded text and attempt to decode it using each possible byte
- Look at each result to see if anything interesting pops out
- Can also be pre-computed if you know a string might be present
- e.g. `This program cannot be run in DOS mode`
- $k \oplus 0=k$, in the pre-ample there’s a lot of 0s, which means the key will be visible
#### Null-Preserving Single Byte XOR Encoding
- Use NULL-preserving single byte encoding scheme
- Rather than xor every byte, this has two rules
1. If byte is zero, or the key value then the byte is skipped
2. Else, xor
- Still reversible
```c
while(c = fgetc(fi), c!=EOF)
{
if (c!=0 && c!=key)
{
c ^= key;
}
fputc(c, fo);
}
```
- Relatively straight-forward to find this code in a disassembler
- Search for `xor` instructions
- There will be several (xor is used to set registers to zero)
- Look out for instructions that:
- XOR constant with a register
- XOR a register with another different register
- Look out for small loops containing `XOR`s
Other encodings
- Using addition and subtraction
- Using bit rotation
- ROT-n (the original ceaser cipher)
- Multibyte (using a longer key)
- Chained or loopback
- Encoding the data with itself
- Base64 encoded
### Base64
Base64 encoding is used to represent binary data in an ASCII string format and is commonly found in malware. The values used are `A-Z a-z 0-9 +/`.
#### Encoding with Base64
- It used 24-bit (3-byte) chunks
- The first character is placed in the most significant position
- The second in the middle 8 bits
- The third in the least significant 8 bits
- Bits are read in blocks of 6 - the number represented is used as an index to the base64 string.
![1653066344.png](img/1653066344.png)
#### Identifying and Decoding Base64
The best way to find this type of encoding is looking for the encoding string.
`ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/`
This will always be stored as a string as it needs to be indexable.
Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.