Files
2026-10-04 15:24:17 +01:00

3.8 KiB

Data Encoding

Malware uses encoding for a variety of reasons; the main one is for encrypting network-based communication.

  • Malware needs to hide its intent
  • This applies both to its operation and to the data it uses
  • Data encoding refers to all forms of content modification used for the purpose of hiding intent
  • Malware will use data encoding to:
    • Hide configuration information
    • Save information to a staging file before stealing it
    • Store strings used by the malware
      • Imagine a key logger, logs what the user is searching for. The file would come up
    • Disguise itself as a legitimate tool

When analysing, the goal is to first find the encryption functions and then use them to decode whatever information is encoded.

Mechanisms for data encoding

  • Malware could (and does) use standard cryptographic algorithms for data encoding
    • These algorithms have high entropy
    • This can be seen in IDA
    • Ransomware will use standard encryption as they want the data to not be decrypted
  • But malware is just as likely to use simple techniques
    • Are small enough to be used in space-constrained environments
    • Less obvious than more complex ciphers
    • Low overhead, little impact on performance
  • Not expecting immunity from being cracked, rather simply looking for an easy way to prevent basic analysis.

XOR Cipher

  • Common mechanism used by malware authors
  • Convenient to use
    • Simple to implement (one instruction)
    • Reversible - same function can encode and decode
Brute Forcing xor encoding
  • Very easy to brute force crack simple xor encoding
  • Only one of 256 possible values used to encode data
  • Simply take a portion of the encoded text and attempt to decode it using each possible byte
  • Look at each result to see if anything interesting pops out
  • Can also be pre-computed if you know a string might be present
    • e.g. This program cannot be run in DOS mode
    • k \oplus 0=k, in the preamble there are a lot of 0s, which means the key will be visible

Null-Preserving Single Byte XOR Encoding

  • Use NULL-preserving single byte encoding scheme
  • Rather than xor every byte, this has two rules
    1. If byte is zero, or the key value then the byte is skipped
    2. Else, xor
  • Still reversible
while(c = fgetc(fi), c!=EOF)
{
    if (c!=0 && c!=key)
    {
        c ^= key;
    }
    fputc(c, fo);
}
  • Relatively straightforward to find this code in a disassembler
  • Search for xor instructions
  • There will be several (xor is used to set registers to zero)
  • Look out for instructions that:
    • XOR constant with a register
    • XOR a register with another different register
  • Look out for small loops containing XORs

Other encodings

  • Using addition and subtraction
  • Using bit rotation
  • ROT-n (the original Caesar cipher)
  • Multibyte (using a longer key)
  • Chained or loopback
    • Encoding the data with itself
  • Base64 encoded

Base64

Base64 encoding is used to represent binary data in an ASCII string format and is commonly found in malware. The values used are A-Z a-z 0-9 +/.

Encoding with Base64

  • It uses 24-bit (3-byte) chunks
    • The first character is placed in the most significant position
    • The second in the middle 8 bits
    • The third in the least significant 8 bits
  • Bits are read in blocks of 6 - the number represented is used as an index to the base64 string.

1653066344.png

Identifying and Decoding Base64

The best way to find this type of encoding is to look for the encoding string.

ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/

This will always be stored as a string as it needs to be indexable.

Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc.