[ << ALL_FEED ]

One-two — and done. Generating FLIRT signatures

More in General

👏 One-two — and done. Generating FLIRT signatures

And we do this to avoid wasting time on recognizing the library code of PureBasic, in which the COM-DLL-Dropper of the ExCobalt group is written.

To start, we will need the PureBasic compiler. After downloading it and installing or unpacking it, we will find all the .lib files. Next, we will need the tools included in Flair:

— pcf — a parser for .lib and .obj files, creates a PAT file from COFF files.
— sigmake — converts the previously created PAT file into a SIG file for IDA.

With their help, we will generate the signatures. To automate the creation of the PAT file, we will use a BAT file with the following contents:


@echo off

\path\pcf.exe -a \path\Debugger.lib 
\path\PureBasic_x86.pat
\path\pcf.exe -a \path\libmariadb.lib 
\path\PureBasic_x86.pat
...
Code language: plaintext (plaintext)

After obtaining the PAT file, we need to convert it into a SIG file. To do this, we will run the following command:

\path\sigmake.exe -n"PureBasic_Windows_X86_LTS_6.03" \path\PureBasic_x86.pat \path\PureBasic_x86.sig
Code language: plaintext (plaintext)

Since collisions occurred during signature generation, we get the following list of files:

— PureBasic_x86.err,
— PureBasic_x86.exc,
— PureBasic_x86.pat.

If there were no collisions, we would immediately get a ready-made SIG file. To eliminate them, we need to edit the EXC file. An example of a collision:


_PB_WriteFloat@8 0B 5366........E8........85C0742D83780400
_PB_WriteInteger@8 0B 5366........E8........85C0742D83780400
_PB_WriteLong@8 0B 5366........E8........85C0742D83780400
Code language: plaintext (plaintext)

We see that three functions have the same signature — we need to choose which one to use.

On the left, next to the name of the desired function, we put +. In this case, the collision affected functions identical in purpose, and we can choose any of them:


_PB_WriteFloat@8 0B 5366........E8........85C0742D83780400
+_PB_WriteInteger@8 0B 5366........E8........85C0742D83780400
_PB_WriteLong@8 0B 5366........E8........85C0742D83780400
Code language: plaintext (plaintext)

But sometimes it affects functions with completely opposite purposes — you can choose any one, but remember or write it down: this will come in handy when the result is obtained.

You also need to delete the line ——— in the EXC file so that the choice is taken into account during repeated signature generation:


;--------- (delete these lines to allow sigmake to read this fil
; add '+' at the start of a line to select a module
; add '-' if you are not sure about the selection
; do nothing if you want to exclude all modules
Code language: SQL (Structured Query Language) (sql)

After the action has been performed for all collisions, you need to repeat the generation. If everything is done correctly, we will get a SIG file. It should be placed in:


%IDA Home%\sig\pc
Code language: plaintext (plaintext)

#reverse #tips #ComDllDropper #ExCobalt #APT #TI
@ptescalator

More from ti_author

More from ti_author

More in General