Skip to main content

Malware Function-based encryption technique

Recent malware often uses techniques to evade detection by cybersecurity products. One of the techniques is the encryption of executable code. Malware analysis techniques for decrypting executable code in memory have existed for some time. However, more recent malware has employed an advanced technique. This function-based encryption technique where the code is encrypted for each function and decrypted only when it is executed has substantially hampered these techniques. An effective way to analyze this technique was to trace the code. Possible methods of tracing are using debuggers and monitoring with tools. Debugger analysis can be successful in analyzing malware using this technique if analysts know a few key points. It is found that using a tracing tool was also effective. It is possible to manually analyze malware using this technique. However, it is also found it difficult to use the detection and analysis methods used so far. By understanding this technique and knowing effective analysis methods, it is necessary to evolve the detection and analysis methods.

sans-malware-function-based-encryption-technique (PDF, 0.93MB)

22 Jun 2022
ByHirokazu Murakami
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Cheap Malware Calls for Cheap Defense: Shellcode and Defense Tools on an SMB Security Budget

Research Paper

This research will examine the varieties of free and open-source tooling available for...

  • 16 Aug 2024

Threat Intelligence-Driven Attack Surface Management

Research Paper

Defenders struggle to keep up with the pace of digital transformation in the face of an expanding...

  • 9 Aug 2022

How to Build and Use an Incident Response Playbook Effectively

Research Paper

An effective incident response playbook provides structure and clarity during high-pressure security events.

  • 25 Jul 2022

Windows 10 vs. Windows 11, What Has Changed?

Research Paper

Windows 10 was released on July 29, 2015. It has since become the most installed desktop operating...

  • 25 Jul 2022

Detecting Unauthorized Behavior From Legitimate Accounts

Research Paper

Incident Responders face an almost insurmountable amount of log events, and the move to the Cloud...

  • 22 Jun 2022

Recover an RSA Private Key from a TLS v1.2 session

Research Paper

Cyberattacks happen every day.Most organizations have administrative and technical controls...

  • 22 Jun 2022

Cyber Guardian Exercise: A Case Study in Brazil to Address Challenges in Cybersecurity and Protect Critical Infrastructure

Research Paper

Discussions of cybersecurity, in particular those associated with critical infrastructure (CI),...

  • 22 Feb 2022

Recommendations for small/medium-sized businesses enabling incident response

Research Paper

Security incidents are inevitable. While large businesses can afford security teams to prepare and...

  • 17 Jan 2022

Black-Box Fuzzing for Android Native Libraries

Research Paper

Many Android application developers are adopting C\C++ native language development in their Android...

  • 12 Jan 2022

Cloud Forensics Triage Framework (CFTF)

Research Paper

Digital media forensic investigations come in multiple forms and span single assets - from thumb...

  • 28 Jul 2021

EDR Evasion: Stranger things in a payload

Research Paper

Tackling enterprise security has many pitfalls. Yet, the emergence of Endpoint Detection & Response...

  • 28 Jul 2021

Machine Learning Techniques for Intrusion Detection

Research Paper

This paper aims to equip intrusion analysts with the basic techniques needed to apply machine...

  • 9 Jun 2021

CIS CSC Controls vs. Ransomware: An Evaluation

Research Paper

Cybercriminals continue to develop and enhance both new and existing ransomware variants, exploiting...

  • 19 May 2021

Missing SQLite Records Analysis

Research Paper

This article will specifically discuss the identification of missing records, within the SQLite...

  • 12 Mar 2021

Insider Threat The Theft of Intellectual Property in Windows 10

Research Paper

The prevalence of the theft of intellectual property investigations has grown over the past years...

  • 11 Mar 2021

A Forensic Analysis of the Encrypting File System

Research Paper

EFS or the Encrypting File System is a feature of the New Technology File System (NTFS). EFS...

  • 24 Feb 2021

Tactical Linguistics: Language Analysis in Cyber Threat Intelligence

Research Paper

The capability to effectively collect and analyze data in strategic foreign languages when...

  • 15 Jan 2021

Practical Process Analysis - Automating Process Log Analysis with PowerShell

Research Paper

Windows event log analysis is an important and often time-consuming part of endpoint forensics. Deep...

  • 29 Dec 2020

Incident Response in a Security Operation Center

Research Paper

Cybercrime dates back to the late 1700s and remains a threat today. By observing current threats,...

  • 27 Aug 2020

Applying the Scientific Method to Threat Hunting

Research Paper

Threat hunting is a proactive approach to discover attackers within an organization. Without the use...

  • 28 May 2020

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.