[ << ALL_FEED ]

Are you using cryptography correctly?

More in General

Are you using cryptography correctly? 🔓

The Advanced Threat Research Group of the Threat Intelligence department often has to solve interesting tasks in the process of reverse engineering malware. This time was no exception. There is a technique known as Execution Guardrails: Environmental Keying — it is needed to restrict the execution of malware to a specific target environment only. For example, it is used by the Decoy Dog group in their operations.

In the sample that came to us for research, this same technique was used: the computer name, which we did not have, was used as the key for the strings employed, and additionally the sample was obfuscated. If the malware was launched on a device other than the one the attacker intended, it crashed — and that is where our research begins.

☠️ It turned out that the malware “crashes” when attempting to call the LoadLibraryA function with a library name passed as non-printable bytes. This set of bytes should represent the name of a library that is decrypted in a loop; at each iteration, a character is taken from the computer name, transformed into an irreversible form using logical operations, and then XORed with the encrypted text and its single-byte constant.

To recover the intermediate key (which is formed as a result of the logical operations), we resorted to a known-plaintext attack. Returning to the LoadLibraryA function: we know that the library name will consist of 13 bytes in ASCII + '\x00' encoding; this way we were able to recover a third of the key, and then, by analogy with other strings, we recovered the remaining part of the key.

String decryption:
F(sym_comp_name) ^ sym_enc ^ cnst_enc = sym_dec
F(sym_comp_name) — logical operations

Obtaining the intermediate key:
sym_dll_name ^ sym_enc ^ cnst_enc = irr_sym_key
irr_sym_key — intermediate key byte, irreversible
Code language: plaintext (plaintext)


The Advanced Threat Research Group recommends one of the platforms for studying cryptanalysis — cryptohack.org.


#tips #reverse #malware #cryptography #TI
@ptescalator

More from ti_author

More from ti_author

More in General