typetechniqueconfidencehighcreated2026-08-17updated2026-09-03obfuscationencryptionsteganographyanti-sandbox

companion-file-encrypted-payload

Malware technique where the executable logic is split across multiple files: a signed or legitimate-appearing PE binary (the "carrier") reads an encrypted payload from one or more companion files at runtime, decrypts it in-memory, and executes. This defeats single-file sandbox detonation because the companion files are required for the payload to materialize.

Mechanism

  1. Carrier PE contains no malicious strings or imports (or minimal surface)
  2. Companion file(s) have benign extensions (.map, .xml, .dat, .log) or no extension
  3. Carrier reads companion via standard file APIs (CreateFileW, ReadFile, MapViewOfFile)
  4. Decryption happens in-memory (AES, XOR, custom, or stream cipher)
  5. Result is executed via reflective PE load, process hollowing, or shellcode injection

Detection Heuristics

  • Large companion files (>1 MB) with entropy >0.95 and no recognizable magic
  • Carrier imports file-mapping APIs but has no obvious reason to read a .map or .xml
  • Companion files found in same directory as the carrier at detonation time
  • CAPE behavioral reports show ReadFile on large non-PE files followed by VirtualAlloc + WriteProcessMemory

Observed Samples

  • 4a78e2ad (kernel-layer.xml — 7.6 MB, entropy 7.90, no magic; InfoPath-signed carrier with Office DLLs) ^[/intel/analyses/4a78e2adf2ab7c257c7c5a960a8edeb0d64fa6ac564f4c06060c92adfa12ae76.html]
  • 642ecaab (network-mon.map — 6.7 MB, entropy 0.99, no magic) ^[raw/analyses/642ecaab/report.md]
  • 9410374b (network-mon.map — 6.8 MB, entropy 7.95, no magic; process.xml — 26.8 KB; same inner payload as 642ecaab) ^[/intel/analyses/9410374bb9ccfb1a8a15aac5a038202e1ce7fb841a5128edf4d348d82db760c3.html]
  • wraith 0ab9a570 (companion-file XOR key decryption)

Related