<aside> 🎯
Decryption [Definition] → Process of transforming encoded or encrypted content back into its original, readable form.
</aside>
<aside>
</aside>
This portion involves using static and dynamic analysis to break down a malware sample and understand how it decrypted its internal configuration. With tools like x64dbg, Ghidra, and CyberChef, I was able to trace how the malware used Windows CryptoAPI functions to generate a key from the string “Thursday” and decrypt a payload that included its Command and Control (C2) domain: shadysite.com.
Repeating the decryption process in CyberChef helped validate the results. Overall, this portion highlights how combining static code analysis with live debugging gives a clearer picture of how malware behaves.
<aside> ✏️
</aside>
<aside>
</aside>
<aside> ⚒️
</aside>
| Tool: | Description: |
|---|---|
| Ghidra | Reverse engineering tool used for analyzing malware. It allows users to disassemble and inspect code, helping them understand how software functions without needing to run it. |
| x64 dbg | An open-source binary debugger for Windows, aimed at malware analysis and reverse engineering of executables you do not have the source code for. |
| Cyberchef | Web source tool that allows encoding, encryption and creating binaries and hexdumps |
| HxD | A freeware hex editor, disk editor, and memory editor for Windows |
Ghidra

CyberChef

HxD

x64 dbg

<aside> ⚙
</aside>
<aside> 🐲
</aside>
Using Ghidra, we were able to examine additional various imports and API calls. By first referencing “CryptDecrypt,” which is often used to decrypt strings, we then opened the decompiler to observe the additional amounts of functions.

Figure 1: Observing CryptDecrypt and the “CALL” indicating calling of the API
The beginning, Crypt AcquireContextW, initializes a CSP (Cryptographic Service Provider) handle (local_res20) which is reserved than for later crypto operations. The CryptCreateHash string and function takes the hashing object using the MD5 algorithm, evidenced by the (local_res20, CALG_MD5) portion. Later, the CryptHashData hashes the string “Thursday” which then becomes the primary basis for taking the decryption key. So essentially the string: “Thursday” via MD5. CryptDeriveKey then derives a session key from the MD5 hash of “Thursday,” using the hexified algorithm: “0x6801.” This acts as a handle is then put into “local_30” which is then later used in CryptDecrypt.

Figure #2: Breakdown of the file into Ghidra, which then references CryptDecrypt in the Decomplier, giving a detailed view on the creation of the MD5 hash object holding the string: “Thursday.”

Figure #3: Highlighting the later portions of the handle that take the hash storing imports and functions, finally being stored into: “local_30”
<aside> 🔢
</aside>
Utilizing HxD, and importing brbconfig.tmp into the software, we are able to then take the contents of the broken down hex and translate it to reflect the contents of the string.
