Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -1,37 +1,37 @@
|
||||
# Data Encoding
|
||||
|
||||
Malware uses encoding for a variety of reasons, the main one is for encrypting network-based communication.
|
||||
Malware uses encoding for a variety of reasons; the main one is for encrypting network-based communication.
|
||||
|
||||
- Malware needs to hide its intent
|
||||
- This applies to both its operation but also to the data it uses
|
||||
- This applies both to its operation and to the data it uses
|
||||
- Data encoding refers to all forms of content modification used for the purpose of hiding intent
|
||||
- Malware will use data encoding to:
|
||||
- Hide configuration information
|
||||
- Save information to a staging file before stealing it
|
||||
- To store strings used by the malware
|
||||
- Imagine a key logger, logs what the user is searching for. The file would come up
|
||||
- Disguise itself as a legitimate tool
|
||||
- Hide configuration information
|
||||
- Save information to a staging file before stealing it
|
||||
- Store strings used by the malware
|
||||
- Imagine a key logger, logs what the user is searching for. The file would come up
|
||||
- Disguise itself as a legitimate tool
|
||||
|
||||
When analysing the goal is to first find the encryption functions and then using that to decode whatever information is encoded.
|
||||
When analysing, the goal is to first find the encryption functions and then use them to decode whatever information is encoded.
|
||||
|
||||
#### Mechanisms for data encoding
|
||||
|
||||
- Malware could (and does) use standard cryptographic algorithms for data encoding
|
||||
- These algorithms have high entropy
|
||||
- This can be seen in IDA
|
||||
- Ransomware will use standard encryption as they want the data to not be decrypted
|
||||
- These algorithms have high entropy
|
||||
- This can be seen in IDA
|
||||
- Ransomware will use standard encryption as they want the data to not be decrypted
|
||||
- But malware is just as likely to use simple techniques
|
||||
- Are small enough to be used in space-constrained environments
|
||||
- Less obvious than more complex ciphers
|
||||
- Low overhead, little impact on performance
|
||||
- Are small enough to be used in space-constrained environments
|
||||
- Less obvious than more complex ciphers
|
||||
- Low overhead, little impact on performance
|
||||
- Not expecting immunity from being cracked, rather simply looking for an easy way to prevent basic analysis.
|
||||
|
||||
#### XOR Cipher
|
||||
|
||||
- Common mechanism used by malware authors
|
||||
- Convenient to use
|
||||
- Simple to implement (one instruction)
|
||||
- Reversible - same function can encode and decode
|
||||
- Simple to implement (one instruction)
|
||||
- Reversible - same function can encode and decode
|
||||
|
||||
##### Brute Forcing xor encoding
|
||||
|
||||
@@ -40,15 +40,15 @@ When analysing the goal is to first find the encryption functions and then using
|
||||
- Simply take a portion of the encoded text and attempt to decode it using each possible byte
|
||||
- Look at each result to see if anything interesting pops out
|
||||
- Can also be pre-computed if you know a string might be present
|
||||
- e.g. `This program cannot be run in DOS mode`
|
||||
- $k \oplus 0=k$, in the pre-ample there’s a lot of 0s, which means the key will be visible
|
||||
- e.g. `This program cannot be run in DOS mode`
|
||||
- $k \oplus 0=k$, in the preamble there are a lot of 0s, which means the key will be visible
|
||||
|
||||
#### Null-Preserving Single Byte XOR Encoding
|
||||
|
||||
- Use NULL-preserving single byte encoding scheme
|
||||
- Rather than xor every byte, this has two rules
|
||||
1. If byte is zero, or the key value then the byte is skipped
|
||||
2. Else, xor
|
||||
1. If byte is zero, or the key value then the byte is skipped
|
||||
2. Else, xor
|
||||
- Still reversible
|
||||
|
||||
```c
|
||||
@@ -62,22 +62,22 @@ while(c = fgetc(fi), c!=EOF)
|
||||
}
|
||||
```
|
||||
|
||||
- Relatively straight-forward to find this code in a disassembler
|
||||
- Relatively straightforward to find this code in a disassembler
|
||||
- Search for `xor` instructions
|
||||
- There will be several (xor is used to set registers to zero)
|
||||
- Look out for instructions that:
|
||||
- XOR constant with a register
|
||||
- XOR a register with another different register
|
||||
- XOR constant with a register
|
||||
- XOR a register with another different register
|
||||
- Look out for small loops containing `XOR`s
|
||||
|
||||
Other encodings
|
||||
|
||||
- Using addition and subtraction
|
||||
- Using bit rotation
|
||||
- ROT-n (the original ceaser cipher)
|
||||
- ROT-n (the original Caesar cipher)
|
||||
- Multibyte (using a longer key)
|
||||
- Chained or loopback
|
||||
- Encoding the data with itself
|
||||
- Encoding the data with itself
|
||||
- Base64 encoded
|
||||
|
||||
### Base64
|
||||
@@ -86,20 +86,20 @@ Base64 encoding is used to represent binary data in an ASCII string format and i
|
||||
|
||||
#### Encoding with Base64
|
||||
|
||||
- It used 24-bit (3-byte) chunks
|
||||
- The first character is placed in the most significant position
|
||||
- The second in the middle 8 bits
|
||||
- The third in the least significant 8 bits
|
||||
- It uses 24-bit (3-byte) chunks
|
||||
- The first character is placed in the most significant position
|
||||
- The second in the middle 8 bits
|
||||
- The third in the least significant 8 bits
|
||||
- Bits are read in blocks of 6 - the number represented is used as an index to the base64 string.
|
||||
|
||||

|
||||
|
||||
#### Identifying and Decoding Base64
|
||||
|
||||
The best way to find this type of encoding is looking for the encoding string.
|
||||
The best way to find this type of encoding is to look for the encoding string.
|
||||
|
||||
`ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/`
|
||||
|
||||
This will always be stored as a string as it needs to be indexable.
|
||||
|
||||
Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.
|
||||
Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.
|
||||
Reference in new issue
Block a user