Companion-File Key Decryption
A defense-evasion technique in which the malware stores its decryption key in a separate file on disk (often with a system-like or benign filename) and reads it at runtime. Without the companion file, static analysis of the PE alone cannot decrypt the payload. Sandboxes that ingest only the primary executable will fail to detonate the real behavior.
Detection / Fingerprint
- Look for
CreateFileA/WorCreateFileWcalls targeting paths under%windir%,%systemroot%, or%temp%with unusual filenames (e.g.,mshlpda32.dll,msvcrt_2.dll,update.bin). - Small read sizes (4–16 bytes) immediately followed by in-memory XOR loops or
VirtualProtect/VirtualAllocRWX allocations. - PE sections with
IMAGE_SCN_MEM_EXECUTE | IMAGE_SCN_MEM_WRITEflags, high entropy, and large virtual-to-raw size discrepancies.
Implementation Patterns Observed
Wraith variant (0ab9a570):
- Resolves
%windir%viaGetEnvironmentVariableA. - Appends
\mshlpda32.dll. - Opens with
GENERIC_READ | OPEN_EXISTING. - Reads exactly 4 bytes into a stack buffer.
- Closes handle.
- Uses those 4 bytes as a rolling-XOR key across
.textand.datasections in-place. - Checks an 8-byte sentinel (
valid_co) after each decryption loop; aborts on mismatch.
Reproduce on Your Own VMs
Goal: Build a minimal companion-file decryptor to understand the sandbox evasion.
Toolchain: Visual Studio 2022 C++ (Win32 console), or MinGW-w64.
Steps:
- Create a small PE with a
.textsection marked RWX. - Encrypt a dummy payload (e.g., shellcode that pops
MessageBoxA) with a 4-byte key. - Store the key in a separate file (e.g.,
C:\test\key.bin). - At runtime, read the key, decrypt the
.textsection in-place, then call through the decrypted payload. - Compile and run with and without the key file. Observe that the binary crashes or does nothing when the companion file is missing.
Verification: Use x64dbg to set a breakpoint on CreateFileA. Watch the path construction, the small read, and the subsequent XOR loop. Compare memory entropy before and after the loop.
Defensive Countermeasures
- Sandbox enrichment: Ensure sandboxes ingest all dropped files, registry modifications, and filesystem artifacts from the initial execution chain. Single-PE detonation is insufficient.
- Telemetry: Alert on small reads (≤16 bytes) from unusual
.dllor.binfiles under%windir%immediately followed byVirtualProtectwithPAGE_EXECUTE_READWRITE. - YARA: Target the companion-file path construction strings (e.g.,
mshlpda32.dll) combined withCreateFileA+ReadFile+ high-entropy sections.
Pages Where Observed
- wraith —
0ab9a570readsmshlpda32.dllfor a 4-byte rolling-XOR key. ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]
Related
- rolling-xor-section-decryption — The specific in-place XOR loop variant used by Wraith.
- rwx-section-self-modifying — Why RWX section flags are a reliable indicator.