typetechniqueconfidencehighcreated2026-08-04updated2026-08-04obfuscationevasiondefense-evasionresearch-target

Companion-File Key Decryption

A defense-evasion technique in which the malware stores its decryption key in a separate file on disk (often with a system-like or benign filename) and reads it at runtime. Without the companion file, static analysis of the PE alone cannot decrypt the payload. Sandboxes that ingest only the primary executable will fail to detonate the real behavior.

Detection / Fingerprint

  • Look for CreateFileA/W or CreateFileW calls targeting paths under %windir%, %systemroot%, or %temp% with unusual filenames (e.g., mshlpda32.dll, msvcrt_2.dll, update.bin).
  • Small read sizes (4–16 bytes) immediately followed by in-memory XOR loops or VirtualProtect/VirtualAlloc RWX allocations.
  • PE sections with IMAGE_SCN_MEM_EXECUTE | IMAGE_SCN_MEM_WRITE flags, high entropy, and large virtual-to-raw size discrepancies.

Implementation Patterns Observed

Wraith variant (0ab9a570):

  1. Resolves %windir% via GetEnvironmentVariableA.
  2. Appends \mshlpda32.dll.
  3. Opens with GENERIC_READ | OPEN_EXISTING.
  4. Reads exactly 4 bytes into a stack buffer.
  5. Closes handle.
  6. Uses those 4 bytes as a rolling-XOR key across .text and .data sections in-place.
  7. Checks an 8-byte sentinel (valid_co) after each decryption loop; aborts on mismatch.

Reproduce on Your Own VMs

Goal: Build a minimal companion-file decryptor to understand the sandbox evasion.

Toolchain: Visual Studio 2022 C++ (Win32 console), or MinGW-w64.

Steps:

  1. Create a small PE with a .text section marked RWX.
  2. Encrypt a dummy payload (e.g., shellcode that pops MessageBoxA) with a 4-byte key.
  3. Store the key in a separate file (e.g., C:\test\key.bin).
  4. At runtime, read the key, decrypt the .text section in-place, then call through the decrypted payload.
  5. Compile and run with and without the key file. Observe that the binary crashes or does nothing when the companion file is missing.

Verification: Use x64dbg to set a breakpoint on CreateFileA. Watch the path construction, the small read, and the subsequent XOR loop. Compare memory entropy before and after the loop.

Defensive Countermeasures

  • Sandbox enrichment: Ensure sandboxes ingest all dropped files, registry modifications, and filesystem artifacts from the initial execution chain. Single-PE detonation is insufficient.
  • Telemetry: Alert on small reads (≤16 bytes) from unusual .dll or .bin files under %windir% immediately followed by VirtualProtect with PAGE_EXECUTE_READWRITE.
  • YARA: Target the companion-file path construction strings (e.g., mshlpda32.dll) combined with CreateFileA + ReadFile + high-entropy sections.

Pages Where Observed

  • wraith — 0ab9a570 reads mshlpda32.dll for a 4-byte rolling-XOR key. ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]

Related