# Data Encoding Malware uses encoding for a variety of reasons; the main one is for encrypting network-based communication. - Malware needs to hide its intent - This applies both to its operation and to the data it uses - Data encoding refers to all forms of content modification used for the purpose of hiding intent - Malware will use data encoding to: - Hide configuration information - Save information to a staging file before stealing it - Store strings used by the malware - Imagine a key logger, logs what the user is searching for. The file would come up - Disguise itself as a legitimate tool When analysing, the goal is to first find the encryption functions and then use them to decode whatever information is encoded. #### Mechanisms for data encoding - Malware could (and does) use standard cryptographic algorithms for data encoding - These algorithms have high entropy - This can be seen in IDA - Ransomware will use standard encryption as they want the data to not be decrypted - But malware is just as likely to use simple techniques - Are small enough to be used in space-constrained environments - Less obvious than more complex ciphers - Low overhead, little impact on performance - Not expecting immunity from being cracked, rather simply looking for an easy way to prevent basic analysis. #### XOR Cipher - Common mechanism used by malware authors - Convenient to use - Simple to implement (one instruction) - Reversible - same function can encode and decode ##### Brute Forcing xor encoding - Very easy to brute force crack simple xor encoding - Only one of 256 possible values used to encode data - Simply take a portion of the encoded text and attempt to decode it using each possible byte - Look at each result to see if anything interesting pops out - Can also be pre-computed if you know a string might be present - e.g. `This program cannot be run in DOS mode` - $k \oplus 0=k$, in the preamble there are a lot of 0s, which means the key will be visible #### Null-Preserving Single Byte XOR Encoding - Use NULL-preserving single byte encoding scheme - Rather than xor every byte, this has two rules 1. If byte is zero, or the key value then the byte is skipped 2. Else, xor - Still reversible ```c while(c = fgetc(fi), c!=EOF) { if (c!=0 && c!=key) { c ^= key; } fputc(c, fo); } ``` - Relatively straightforward to find this code in a disassembler - Search for `xor` instructions - There will be several (xor is used to set registers to zero) - Look out for instructions that: - XOR constant with a register - XOR a register with another different register - Look out for small loops containing `XOR`s Other encodings - Using addition and subtraction - Using bit rotation - ROT-n (the original Caesar cipher) - Multibyte (using a longer key) - Chained or loopback - Encoding the data with itself - Base64 encoded ### Base64 Base64 encoding is used to represent binary data in an ASCII string format and is commonly found in malware. The values used are `A-Z a-z 0-9 +/`. #### Encoding with Base64 - It uses 24-bit (3-byte) chunks - The first character is placed in the most significant position - The second in the middle 8 bits - The third in the least significant 8 bits - Bits are read in blocks of 6 - the number represented is used as an index to the base64 string. ![1653066344.png](img/1653066344.png) #### Identifying and Decoding Base64 The best way to find this type of encoding is to look for the encoding string. `ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/` This will always be stored as a string as it needs to be indexable. Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.