[ << ALL_FEED ]

Learning to Recover VMProtect Imports

More in General

Learning to Recover VMProtect Imports ⚙️

VMProtect is one of the most widely used malware protectors. At the same time, attackers are often lazy and use only simple protection options — obfuscation of the entry point and imports.

Earlier we already learned how to set up a virtual environment for debugging malware, and also got acquainted with the Speakeasy emulator. Let’s use this knowledge to try to recover VMP imports.

Let’s dump the process (it’s important that the OEP has been reached at the moment of dumping, so that VMP initializes all internal structures for operation), open the dump in IDA, and let it mark up the library symbols.

Next, let’s look at what the obfuscated imports look like (screenshot 1). It’s clear that VMP inserted a call to its own section instead of a call to the original library, and the called function consists of a bunch of (at first glance) garbage instructions.

❗️ However, this is not entirely true. If you step into this call in the debugger, at some point the real API address will end up on the stack. See screenshot 2 for an example trace.

Let’s try to automate this. First, we need to collect the list of calls we’re interested in. The logic is simple: the call goes from the text section into the VMP section (screenshot 3). For brevity, we’ll assume that the addresses of these sections in the dump are already known to us.

Let’s write the logic for resolving the obtained addresses; to do this, we’ll load the module from the dump as shellcode into Speakeasy and add a hook that checks each instruction for ret. Additionally, we’ll limit the maximum trace depth and save the number of steps for each import. The final contents of the hook, as well as the function for initializing the shellcode in the emulator, can be seen in screenshot 4.

The function for launching the emulator is presented in screenshot 5. It runs several times to work around the situation where, after executing several garbage instructions, its internal state gets corrupted and attempts to read anything afterward always fail with errors.

Now let’s put it all together and look at the results (screenshot 6). Based on the collected information, most of the imports in the original sample can be labeled.

👀 Summary: we’ve learned to recover VMP imports with minimal effort, which significantly simplifies the analysis of such samples. If desired, a similar approach can be applied to running processes, as well as to patch and rebuild the sample with the correct API addresses, as, for example, vmpdump does.

#ti #malware #tip #VMProtect
@ptescalator

More from ti_author

More from ti_author

More in General