Rolling XOR Section Decryption
An in-place decryption routine that XORs each byte of a PE section with a key byte plus a running delta (typically the loop index or an incrementing counter). The key itself is often read from a companion file, registry value, or embedded at a fixed offset. Sentinel bytes at the end of the decrypted region validate success.
Detection / Fingerprint
- Tight loops inside the PE entry point that read from a section base, XOR with a variable key, and write back to the same address.
- Sentinel checks immediately after the loop (e.g., comparing the last 8 bytes against a known string like
valid_co). - High section entropy (>7.5) dropping abruptly after the loop completes in a debugger.
Implementation Patterns Observed
Wraith variant (0ab9a570):
- Key: 4 bytes from
%windir%\mshlpda32.dll. - Algorithm:
decrypted[i] = encrypted[i] ^ (key[i % 4] + delta)wheredeltaincrements per iteration. - Two passes: one for
.text(base0x402000), one for.data(base0x435000). - Sentinel:
valid_co(8 bytes) checked after each pass.
Reproduce on Your Own VMs
See companion-file-key-decryption for a full build recipe. The delta is the distinguishing detail.
Defensive Countermeasures
- Monitor for self-modifying
.textvia EDR memory-protection telemetry. - Use hardware breakpoints on write access to the
.textbase address in a debugger.
Pages Where Observed
- wraith —
0ab9a570uses rolling XOR + delta with companion key. ^[/intel/analyses/0ab9a5703d797646e0d3d4d660d7a816bf0f8d720802183b82d99544c6f9b95a.html]
Related
- companion-file-key-decryption — Where the key originates.
- rwx-section-self-modifying — Why the section must be writable at runtime.