This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+31 -31
View File
@@ -1,37 +1,37 @@
# Data Encoding
Malware uses encoding for a variety of reasons, the main one is for encrypting network-based communication.
Malware uses encoding for a variety of reasons; the main one is for encrypting network-based communication.
- Malware needs to hide its intent
- This applies to both its operation but also to the data it uses
- This applies both to its operation and to the data it uses
- Data encoding refers to all forms of content modification used for the purpose of hiding intent
- Malware will use data encoding to:
- Hide configuration information
- Save information to a staging file before stealing it
- To store strings used by the malware
- Imagine a key logger, logs what the user is searching for. The file would come up
- Disguise itself as a legitimate tool
- Hide configuration information
- Save information to a staging file before stealing it
- Store strings used by the malware
- Imagine a key logger, logs what the user is searching for. The file would come up
- Disguise itself as a legitimate tool
When analysing the goal is to first find the encryption functions and then using that to decode whatever information is encoded.
When analysing, the goal is to first find the encryption functions and then use them to decode whatever information is encoded.
#### Mechanisms for data encoding
- Malware could (and does) use standard cryptographic algorithms for data encoding
- These algorithms have high entropy
- This can be seen in IDA
- Ransomware will use standard encryption as they want the data to not be decrypted
- These algorithms have high entropy
- This can be seen in IDA
- Ransomware will use standard encryption as they want the data to not be decrypted
- But malware is just as likely to use simple techniques
- Are small enough to be used in space-constrained environments
- Less obvious than more complex ciphers
- Low overhead, little impact on performance
- Are small enough to be used in space-constrained environments
- Less obvious than more complex ciphers
- Low overhead, little impact on performance
- Not expecting immunity from being cracked, rather simply looking for an easy way to prevent basic analysis.
#### XOR Cipher
- Common mechanism used by malware authors
- Convenient to use
- Simple to implement (one instruction)
- Reversible - same function can encode and decode
- Simple to implement (one instruction)
- Reversible - same function can encode and decode
##### Brute Forcing xor encoding
@@ -40,15 +40,15 @@ When analysing the goal is to first find the encryption functions and then using
- Simply take a portion of the encoded text and attempt to decode it using each possible byte
- Look at each result to see if anything interesting pops out
- Can also be pre-computed if you know a string might be present
- e.g. `This program cannot be run in DOS mode`
- $k \oplus 0=k$, in the pre-ample there’s a lot of 0s, which means the key will be visible
- e.g. `This program cannot be run in DOS mode`
- $k \oplus 0=k$, in the preamble there are a lot of 0s, which means the key will be visible
#### Null-Preserving Single Byte XOR Encoding
- Use NULL-preserving single byte encoding scheme
- Rather than xor every byte, this has two rules
1. If byte is zero, or the key value then the byte is skipped
2. Else, xor
1. If byte is zero, or the key value then the byte is skipped
2. Else, xor
- Still reversible
```c
@@ -62,22 +62,22 @@ while(c = fgetc(fi), c!=EOF)
}
```
- Relatively straight-forward to find this code in a disassembler
- Relatively straightforward to find this code in a disassembler
- Search for `xor` instructions
- There will be several (xor is used to set registers to zero)
- Look out for instructions that:
- XOR constant with a register
- XOR a register with another different register
- XOR constant with a register
- XOR a register with another different register
- Look out for small loops containing `XOR`s
Other encodings
- Using addition and subtraction
- Using bit rotation
- ROT-n (the original ceaser cipher)
- ROT-n (the original Caesar cipher)
- Multibyte (using a longer key)
- Chained or loopback
- Encoding the data with itself
- Encoding the data with itself
- Base64 encoded
### Base64
@@ -86,20 +86,20 @@ Base64 encoding is used to represent binary data in an ASCII string format and i
#### Encoding with Base64
- It used 24-bit (3-byte) chunks
- The first character is placed in the most significant position
- The second in the middle 8 bits
- The third in the least significant 8 bits
- It uses 24-bit (3-byte) chunks
- The first character is placed in the most significant position
- The second in the middle 8 bits
- The third in the least significant 8 bits
- Bits are read in blocks of 6 - the number represented is used as an index to the base64 string.
![1653066344.png](img/1653066344.png)
#### Identifying and Decoding Base64
The best way to find this type of encoding is looking for the encoding string.
The best way to find this type of encoding is to look for the encoding string.
`ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/`
This will always be stored as a string as it needs to be indexable.
Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.
Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.