companion-file-encrypted-payload
Malware technique where the executable logic is split across multiple files: a signed or legitimate-appearing PE binary (the "carrier") reads an encrypted payload from one or more companion files at runtime, decrypts it in-memory, and executes. This defeats single-file sandbox detonation because the companion files are required for the payload to materialize.
Mechanism
- Carrier PE contains no malicious strings or imports (or minimal surface)
- Companion file(s) have benign extensions (
.map,.xml,.dat,.log) or no extension - Carrier reads companion via standard file APIs (
CreateFileW,ReadFile,MapViewOfFile) - Decryption happens in-memory (AES, XOR, custom, or stream cipher)
- Result is executed via reflective PE load, process hollowing, or shellcode injection
Detection Heuristics
- Large companion files (>1 MB) with entropy >0.95 and no recognizable magic
- Carrier imports file-mapping APIs but has no obvious reason to read a
.mapor.xml - Companion files found in same directory as the carrier at detonation time
- CAPE behavioral reports show
ReadFileon large non-PE files followed byVirtualAlloc+WriteProcessMemory
Observed Samples
4a78e2ad(kernel-layer.xml— 7.6 MB, entropy 7.90, no magic; InfoPath-signed carrier with Office DLLs) ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]642ecaab(network-mon.map— 6.7 MB, entropy 0.99, no magic) ^[raw/analyses/642ecaab/report.md]9410374b(network-mon.map— 6.8 MB, entropy 7.95, no magic;process.xml— 26.8 KB; same inner payload as642ecaab) ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]- wraith
0ab9a570(companion-file XOR key decryption)
Related
- signed-carrier-combo — the signed-carrier + companion-file combination
- steam-error-reporter-masquerade
- iexpress-sfx-dropper
- 7z-sfx-dropper