105 lines
3.8 KiB
Markdown
105 lines
3.8 KiB
Markdown
# Data Encoding
|
||
|
||
Malware uses encoding for a variety of reasons, the main one is for encrypting network-based communication.
|
||
|
||
- Malware needs to hide its intent
|
||
- This applies to both its operation but also to the data it uses
|
||
- Data encoding refers to all forms of content modification used for the purpose of hiding intent
|
||
- Malware will use data encoding to:
|
||
- Hide configuration information
|
||
- Save information to a staging file before stealing it
|
||
- To store strings used by the malware
|
||
- Imagine a key logger, logs what the user is searching for. The file would come up
|
||
- Disguise itself as a legitimate tool
|
||
|
||
When analysing the goal is to first find the encryption functions and then using that to decode whatever information is encoded.
|
||
|
||
#### Mechanisms for data encoding
|
||
|
||
- Malware could (and does) use standard cryptographic algorithms for data encoding
|
||
- These algorithms have high entropy
|
||
- This can be seen in IDA
|
||
- Ransomware will use standard encryption as they want the data to not be decrypted
|
||
- But malware is just as likely to use simple techniques
|
||
- Are small enough to be used in space-constrained environments
|
||
- Less obvious than more complex ciphers
|
||
- Low overhead, little impact on performance
|
||
- Not expecting immunity from being cracked, rather simply looking for an easy way to prevent basic analysis.
|
||
|
||
#### XOR Cipher
|
||
|
||
- Common mechanism used by malware authors
|
||
- Convenient to use
|
||
- Simple to implement (one instruction)
|
||
- Reversible - same function can encode and decode
|
||
|
||
##### Brute Forcing xor encoding
|
||
|
||
- Very easy to brute force crack simple xor encoding
|
||
- Only one of 256 possible values used to encode data
|
||
- Simply take a portion of the encoded text and attempt to decode it using each possible byte
|
||
- Look at each result to see if anything interesting pops out
|
||
- Can also be pre-computed if you know a string might be present
|
||
- e.g. `This program cannot be run in DOS mode`
|
||
- $k \oplus 0=k$, in the pre-ample there’s a lot of 0s, which means the key will be visible
|
||
|
||
#### Null-Preserving Single Byte XOR Encoding
|
||
|
||
- Use NULL-preserving single byte encoding scheme
|
||
- Rather than xor every byte, this has two rules
|
||
1. If byte is zero, or the key value then the byte is skipped
|
||
2. Else, xor
|
||
- Still reversible
|
||
|
||
```c
|
||
while(c = fgetc(fi), c!=EOF)
|
||
{
|
||
if (c!=0 && c!=key)
|
||
{
|
||
c ^= key;
|
||
}
|
||
fputc(c, fo);
|
||
}
|
||
```
|
||
|
||
- Relatively straight-forward to find this code in a disassembler
|
||
- Search for `xor` instructions
|
||
- There will be several (xor is used to set registers to zero)
|
||
- Look out for instructions that:
|
||
- XOR constant with a register
|
||
- XOR a register with another different register
|
||
- Look out for small loops containing `XOR`s
|
||
|
||
Other encodings
|
||
|
||
- Using addition and subtraction
|
||
- Using bit rotation
|
||
- ROT-n (the original ceaser cipher)
|
||
- Multibyte (using a longer key)
|
||
- Chained or loopback
|
||
- Encoding the data with itself
|
||
- Base64 encoded
|
||
|
||
### Base64
|
||
|
||
Base64 encoding is used to represent binary data in an ASCII string format and is commonly found in malware. The values used are `A-Z a-z 0-9 +/`.
|
||
|
||
#### Encoding with Base64
|
||
|
||
- It used 24-bit (3-byte) chunks
|
||
- The first character is placed in the most significant position
|
||
- The second in the middle 8 bits
|
||
- The third in the least significant 8 bits
|
||
- Bits are read in blocks of 6 - the number represented is used as an index to the base64 string.
|
||
|
||

|
||
|
||
#### Identifying and Decoding Base64
|
||
|
||
The best way to find this type of encoding is looking for the encoding string.
|
||
|
||
`ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/`
|
||
|
||
This will always be stored as a string as it needs to be indexable.
|
||
|
||
Custom encodings can be performed easily by modifying the encoding string - for example putting the lower case first, dispersing numbers within the letters etc. |