Are you using cryptography correctly?

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
The Advanced Threat Research Group of the Threat Intelligence department often has to solve interesting tasks in the process of reverse engineering malware. This time was no exception. There is a technique known as Execution Guardrails: Environmental Keying — it is needed to restrict the execution of malware to a specific target environment only. For example, it is used by the Decoy Dog group in their operations.
In the sample that came to us for research, this same technique was used: the computer name, which we did not have, was used as the key for the strings employed, and additionally the sample was obfuscated. If the malware was launched on a device other than the one the attacker intended, it crashed — and that is where our research begins.
☠️ It turned out that the malware “crashes” when attempting to call the
LoadLibraryA function with a library name passed as non-printable bytes. This set of bytes should represent the name of a library that is decrypted in a loop; at each iteration, a character is taken from the computer name, transformed into an irreversible form using logical operations, and then XORed with the encrypted text and its single-byte constant. To recover the intermediate key (which is formed as a result of the logical operations), we resorted to a known-plaintext attack. Returning to the
LoadLibraryA function: we know that the library name will consist of 13 bytes in ASCII + '\x00' encoding; this way we were able to recover a third of the key, and then, by analogy with other strings, we recovered the remaining part of the key.String decryption:
F(sym_comp_name) ^ sym_enc ^ cnst_enc = sym_dec
F(sym_comp_name) — logical operations
Obtaining the intermediate key:
sym_dll_name ^ sym_enc ^ cnst_enc = irr_sym_key
irr_sym_key — intermediate key byte, irreversible
Code language: plaintext (plaintext)The Advanced Threat Research Group recommends one of the platforms for studying cryptanalysis — cryptohack.org.

#tips #reverse #malware #cryptography #TI
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



