Sample

Metadata

SHA256
75da9dfe4d0ef6db1d68533ef66a70d4c26230fc82e50e6428f4931800f7b3b2
Difficulty
medium
Platform
Windows
Tags
api hashing shellcode stage 2 x64
Likes
0
Views
34
Submitter
0xca5ade19a931

Analysis

Goal

This sample is a second stage payload shellcode extracted from a loader. The goal is to understand its API hashing algorithm and to decrypt the third-stage payload. In addition tampering with security products as evasion techniques can be identified. How is the third-stage payload executed?

Description

The shellcode reads the API hashes from a buffer and replaces their values with the addresses of the resolved functions.
See if you can determine what API hashing algorithm is used.
Can you identify the decryption algorithm used to extract the payload?
The third-stage payload is an executable that is reflectively loaded and executed.

Recommended Tools

binaryninja ghidra

Comments

Please login to view and post comments.