<aside> 🎯

Decryption [Definition] → Process of transforming encoded or encrypted content back into its original, readable form.

</aside>

<aside>

High-Level Summary:

</aside>

This portion involves using static and dynamic analysis to break down a malware sample and understand how it decrypted its internal configuration. With tools like x64dbg, Ghidra, and CyberChef, I was able to trace how the malware used Windows CryptoAPI functions to generate a key from the string “Thursday” and decrypt a payload that included its Command and Control (C2) domain: shadysite.com.

Repeating the decryption process in CyberChef helped validate the results. Overall, this portion highlights how combining static code analysis with live debugging gives a clearer picture of how malware behaves.

<aside> ✏️

Definitions

</aside>


<aside>

Analysis Reviewed

</aside>

<aside> ⚒️

Tools Used in Analysis

</aside>

Tool: Description:
Ghidra Reverse engineering tool used for analyzing malware. It allows users to disassemble and inspect code, helping them understand how software functions without needing to run it.
x64 dbg An open-source binary debugger for Windows, aimed at malware analysis and reverse engineering of executables you do not have the source code for.
Cyberchef Web source tool that allows encoding, encryption and creating binaries and hexdumps
HxD A freeware hex editor, disk editor, and memory editor for Windows

<aside> ⚙

Limited Imports Examples

</aside>

<aside> 🐲

Ghidra Analysis of Additional Functions

</aside>

  1. Using Ghidra, we were able to examine additional various imports and API calls. By first referencing “CryptDecrypt,” which is often used to decrypt strings, we then opened the decompiler to observe the additional amounts of functions.

    Screenshot 2025-05-01 at 9.45.48 PM.png

Figure 1: Observing CryptDecrypt and the “CALL” indicating calling of the API

  1. Among these included the called functions: CryptCreateHash, CryptHashData, CryptDeriveKey, and CryptEncrypt.

The beginning, Crypt AcquireContextW, initializes a CSP (Cryptographic Service Provider) handle (local_res20) which is reserved than for later crypto operations. The CryptCreateHash string and function takes the hashing object using the MD5 algorithm, evidenced by the (local_res20, CALG_MD5) portion. Later, the CryptHashData hashes the string “Thursday” which then becomes the primary basis for taking the decryption key. So essentially the string: “Thursday” via MD5. CryptDeriveKey then derives a session key from the MD5 hash of “Thursday,” using the hexified algorithm: “0x6801.” This acts as a handle is then put into “local_30” which is then later used in CryptDecrypt.

Screenshot 2025-05-01 at 9.46.16 PM.png

Figure #2: Breakdown of the file into Ghidra, which then references CryptDecrypt in the Decomplier, giving a detailed view on the creation of the MD5 hash object holding the string: “Thursday.”

Screenshot 2025-05-01 at 10.04.42 PM.png

Figure #3: Highlighting the later portions of the handle that take the hash storing imports and functions, finally being stored into: “local_30”

<aside> 🔢

Decoding Hex Code Using HxD to Verify String

</aside>

Utilizing HxD, and importing brbconfig.tmp into the software, we are able to then take the contents of the broken down hex and translate it to reflect the contents of the string.

Screenshot 2025-05-01 at 10.10.14 PM.png