typetechniqueconfidencehighcreated2026-08-04updated2026-08-04obfuscationevasiondefense-evasion

Rolling XOR Section Decryption

An in-place decryption routine that XORs each byte of a PE section with a key byte plus a running delta (typically the loop index or an incrementing counter). The key itself is often read from a companion file, registry value, or embedded at a fixed offset. Sentinel bytes at the end of the decrypted region validate success.

Detection / Fingerprint

  • Tight loops inside the PE entry point that read from a section base, XOR with a variable key, and write back to the same address.
  • Sentinel checks immediately after the loop (e.g., comparing the last 8 bytes against a known string like valid_co).
  • High section entropy (>7.5) dropping abruptly after the loop completes in a debugger.

Implementation Patterns Observed

Wraith variant (0ab9a570):

  • Key: 4 bytes from %windir%\mshlpda32.dll.
  • Algorithm: decrypted[i] = encrypted[i] ^ (key[i % 4] + delta) where delta increments per iteration.
  • Two passes: one for .text (base 0x402000), one for .data (base 0x435000).
  • Sentinel: valid_co (8 bytes) checked after each pass.

Reproduce on Your Own VMs

See companion-file-key-decryption for a full build recipe. The delta is the distinguishing detail.

Defensive Countermeasures

  • Monitor for self-modifying .text via EDR memory-protection telemetry.
  • Use hardware breakpoints on write access to the .text base address in a debugger.

Pages Where Observed

  • wraith — 0ab9a570 uses rolling XOR + delta with companion key. ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]

Related