An implementation method of an automated unpacking engine for malicious files

The automated shell removal engine leverages cloud-based rules and precise disassembly to efficiently identify and decrypt shell-protected binaries, addressing inefficiencies in existing technologies and enhancing malware analysis capabilities.

CN113868648BActive Publication Date: 2025-07-15NANJING FIBERHOME COMM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111052133.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-08
Publication Date
2025-07-15
Estimated Expiration
2041-09-08

AI Technical Summary

Technical Problem

The existing malicious program shelling technology makes it difficult for detection tools to identify and unshell efficiently and accurately. The traditional virtual machine shelling technology is inefficient and costly, and the cloud MD5 method has a high false alarm rate, which lacks universality and flexibility.

Method used

The cloud-based rule library is loaded, and the automated shelling of malicious files is achieved through steps such as simulating PE loaders, disassembly instruction analysis, breakpoint setting and memory repair. Multi-point memory scanning and high-precision disassembly identify shell features, and quickly locate and repair shelling codes.

Benefits of technology

It realizes efficient and accurate cross-platform shelling, reduces system resource usage, supports X86/X64 architecture, is suitable for Linux environments, and simplifies the static analysis work of security research engineers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113868648B_ABST
    Figure CN113868648B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for implementing an automated unpacking engine for malicious files. This method realizes the automated unpacking engine by loading a cloud rule library and supports the characteristics of high efficiency and fast running speed for unpacking. This method identifies various packed PE files, adopts multi-point dynamic memory scanning, simulates PE loading, simulates breakpoints, has a high-precision disassembly recognition mechanism, and uses the memory capture mirroring technology to quickly locate the shell features and quickly unpack and repair. The automated unpacking engine of the present invention can not only quickly unpack and repair the unpacked files, but also assist security research engineers in quickly extracting the malicious samples and traffic characteristics after unpacking and support unpacking analysis of other malicious samples in a third-party sandbox environment, bringing a certain improvement in the ability of network security traffic perception.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention mainly relates to an automated unpacking engine and method for executable files after traffic restoration. Background Art

[0002] In global network security traffic awareness, a large number of malicious programs (such as viruses, Trojans, worms, etc.) generally use some advanced software protection technologies to avoid scanning and killing by anti-virus software after traffic restoration. The complex program packing technology is a typical representative among them. According to statistics, currently, the proportion of malicious

[0003] code that has been packed has exceeded 80%. This development trend of malicious code has brought huge challenges to detection tools. Therefore, how to restore the program content and obtain the normal execution order of the program is the focus of research on malicious code detection technology. Currently, there are mainly two ways of unpacking analysis: one is to use manual unpacking,

[0004] and the other is to use a dedicated unpacking script for targeted unpacking. Both of these ways have obvious defects, such as lack of generality, difficulty in keeping up with the progress of packing technology and the speed of packing code iteration, and the need to consume a large amount of manpower and material resources.

[0005] Currently, the automated unpacking technology still uses virtual machine unpacking as the traditional technology. It supports most packed programs. Because of the problem of the X86 emulator, it needs to simulate a large number of CPU instructions and operation logics. When running the shell code, the recognition efficiency for a large number of floating-point operations, internal operations of function functions, and calls of classes is extremely poor, and the unpacking speed is slow and the accuracy is low. When encountering large-scale traffic restoration files, there will be an extremely heavy load capacity, which requires a high system requirement, and the cost of iteration and cross-platform is extremely high.

[0006] In addition, in order not to use virtual machine unpacking technology for unpacking and reduce the time cost, many security manufacturers use the cloud MD5 method to push to the local for identification. As long as the shell MD5 is found to be similar, the packed program is reported to prompt the user. In this way, the accuracy is very low, and the false alarm cost is increased.

[0007] Therefore, there is an urgent need for an automated unpacking engine with high efficiency, high accuracy, compatibility with various platforms, and cost reduction. At present, the automated unpacking engine can not only complete the shell recognition rate before unpacking, but also efficiently and quickly locate the decryption algorithm parts of unknown shells and known shells, so as to achieve the purpose of rapid decompression, and better assist security research engineers in quickly identifying malicious samples and improving the efficiency of traffic extraction. Summary of the Invention

[0008] In view of the deficiencies of traditional virtual machine unpacking technologies, the present invention discloses an engine for realizing automatic unpacking by loading a cloud rule library, which supports high efficiency and fast running speed, can perform automatic process analysis and feature matching on binary programs with known or unknown shells, and then perform unpacking and repair, so as to assist engineers related to security research in extracting and analyzing malicious sample traffic during static analysis.

[0009] To solve the above technical problems, the present invention adopts the following technical solutions:

[0010] A method for realizing an automatic unpacking engine for malicious files, comprising the following steps:

[0011] Step S1, loading a cloud shell rule library;

[0012] Step S2, reading the binary stream of the PE file into memory and executing it;

[0013] Step S3, the disassembly instruction parsing module identifies specific shell features and the shell decompression location;

[0014] Step S4, locating the decryption code position of specific shell features, setting breakpoints and decrypting the file code before shelling;

[0015] Step S5, applying for memory and copying the decrypted code segment to a new memory space;

[0016] Step S6, repairing the PE code segment in the new memory space;

[0017] Step S7, dumping the PE code segment in the new memory space through the file dump module and mirroring and saving it to a local file.

[0018] Further, the specific steps of step S2 include:

[0019] First, reading the binary stream of the PE file through an emulated PE loader and mapping it to memory;

[0020] Then, locating the target block information of the PE file by judging the PE header file format structure features;

[0021] Next, traversing the import / export table, reading the tls resource relocation information, and repairing the obtained block information through the inner layer repair module of the PE file.

[0022] Further, the specific content of step S3 includes:

[0023] First, the disassembly instruction parsing module parses the current opcode code in memory into the corresponding X86 or X64 assembly code

[0024] Then, the general shell recognition and decryption data flow algorithm module dynamically recognizes the specific shell features and the shell decompression location

[0025] Furthermore, in step S4

[0026] First, the general shell recognition and decryption data flow algorithm module recognizes the code parsed by the opcode of the disassembly instruction parsing module in step S3;

[0027] Then, in the way of setting software breakpoints or hardware execution breakpoints, set breakpoints at the code location pointed to by the opcode algorithm feature EIP of the target;

[0028] Next, call the OEP decentralized recognition module to perform decentralized multi-point matching of the OEP entry before shelling on the decrypted code segment, or trace the OEP storage code of the real program through the path search method. In this process, it is equivalent to finding the real OEP in the decrypted code segment and performing matching through multi-mode features, which is a relationship of feature matching to find the real original program entry in the decrypted PE file code segment.

[0029] Furthermore, in step S6, call the IAT repair module to recognize and repair the API function table called by the current unpacked target program in the original input table, and then call the tls relocation repair module to dynamically repair the tls position of the base address relocation after unpacking to ensure the normal operation of the program after unpacking.

[0030] Furthermore, the file dump module described in step S7 includes a PE file dump module, a section reconstruction module, an inner layer capture image module, and a new OEP calculation module. After the IAT repair module and the tls relocation repair module are completed, call the memory capture image module to perform full memory capture on the position from the image base address entry to the resource section in the PE memory, then call the PE file dump module to dump it to the disk, and then call the section reconstruction module to add a new section to the dumped dump file to store the repaired IAT table code, and call the new OEP calculation module to perform virtual relative addresses on the current image base address. After obtaining the new OEP entry address, fill it into the local dump file to complete all unpacking operations and generate a new unpacked binary PE executable file

[0031] Beneficial effects: Compared with the prior art, the cloud rule library of the present invention is updated quickly. With the help of the capabilities of backend machine learning, the latest shell rule library is quickly pushed to the front end for automatic unpacking. Its unpacking ability is due to the virtual machine method, without relying on virtual operations, saving CPU switching time and not occupying system resources. It is applicable to platforms with X86 / X64 architectures, has high portability, can be secondarily developed under Linux and can be used across platforms.

[0032] The present invention is applicable to a fast, general and effective unpacking method for unpacking a malicious sample from traffic in network security where there is a packed program, which simplifies the static analysis and traffic extraction work of security research engineers on malicious samples. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 It is a schematic diagram of the logical flow of the automated unpacking engine for malicious files according to the present invention;

[0034] Figure 2 It is a block diagram of the functional modules of the automated unpacking engine for malicious files according to the present invention;

[0035] Figure 3 It is the binary malicious sample file extracted in the embodiment of the present invention

[0036] Figure 4 It is the cloud shell feature library loaded in the embodiment of the present invention

[0037] Figure 5 It is the PE file read in the embodiment of the present invention

[0038] Figure 6 It is the shell feature identified by disassembly in the embodiment of the present invention

[0039] Figure 7 It is a location diagram of the official shell decryption code in the embodiment of the present invention;

[0040] Figure 8 It is a breakpoint schematic diagram of the code interruption position set in the embodiment of the present invention.

[0041] Figure 9 It is the new memory mirror PE code segment after repair in the embodiment of the present invention DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] The present invention will be further clarified below with reference to the drawings and specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention. After reading the present invention, various equivalent modifications of the present invention by those skilled in the art fall within the scope defined by the appended claims of this application.

[0043] Implementation method of an automated unpacking engine for malicious files. This method identifies various packed PE files, uses multi-point dynamic memory scanning, simulates PE loading, simulates breakpoints, and has a highly accurate disassembly recognition mechanism. It quickly locates the shell features through memory capture mirroring technology and performs rapid unpacking and repair. The automated unpacking engine can not only quickly unpack and repair the unpacked files, but also assist security research engineers in quickly extracting the unpacked malicious samples and traffic characteristics, and support unpacking analysis of other malicious samples in a third-party sandbox environment, bringing a certain improvement in the ability of network security traffic perception. The implementation and method of the automated unpacking engine for malicious files of the present invention include the following modules, such as Figure 2 as shown below:

[0044] Simulated PE file loader module: File mapping to memory module, PE file format checking module, traversing PE file export table and import table module, reading tls resource relocation information module, PE file memory repair module. Among them, the file mapping to memory module loads the PE file after traffic restoration and calls the PE file format checking module, then calls the traversing PE file table and import module and the reading tls resource relocation information module. After that, the PE file memory repair module repairs all the obtained block information above, and then calls the X86 / X64 disassembly instruction parsing module to perform opcode parsing on the file.

[0045] X86 / X64 disassembly instruction parsing module: Identifies disassembly methods through the opcode in the stream of the file read and mapped in memory, analyzes each opcode code one by one and converts it into the corresponding X86 and X64 assembly codes, and arranges them using the doubly linked list storage method and the multi-dimensional array method. It can quickly and accurately identify control jump statements, floating-point operations, logical AND / OR, conditional judgments, multi-dimensional addressing methods, out-of-order binary bytecodes, out-of-order flower codes, and inflated random codes.

[0046] The functions of the general shell recognition and decryption data stream algorithm module include: decompression algorithm feature recognition module, dynamic memory fast scanning module, software and hardware breakpoint setting module, OEP decentralized recognition module. Among them, the dynamic memory fast scanning module is called to recognize the code after opcode parsing by the disassembly engine module through the decompression algorithm feature recognition module, and then the software / hardware breakpoint setting module is called to set breakpoints at the code position pointed to by the EIP of the opcode algorithm feature of the target and let the program run to the selected breakpoint position. Then the OEP decentralized recognition module is called to perform decentralized multi-point matching and path search of the OEP entry before shelling on the decrypted code segment to trace to the OEP entry code of the real program.

[0047] The composition of the PE file repair module includes: the IAT repair module and the tls relocation repair module. After the OEP decentralized recognition module completes the recognition of the decrypted oep code, the IAT repair module is called to recognize the API function table called by the current unpacked target program and repair the API functions in the original input table. Then, after calling the tls relocation repair module to perform dynamic repair on the TLS position of the unpacked base address relocation, it is ensured that the program runs normally after unpacking.

[0048] The composition of the file dump module includes: the PE file dump module, the section reconstruction module, the memory capture image module, and the new OEP calculation module. After the IAT repair module and the tls relocation repair module are completed, the memory capture image module is called to perform full memory capture on the position from the image base address entry to the resource section in the PE memory, and then the PE file dump module is called to dump it to the disk. Then, the section reconstruction module is called to add a new section to the currently dumped dump file to store the repaired IAT table code. Then, the new OEP calculation module is called to calculate the new OEP entry address as the image base address + virtual relative address and fill it into the local dump file, completing all the above unpacking operations and generating a new unpacked binary PE executable file.

[0049] As Figure 1 shown, the logical process of this embodiment includes:

[0050] The first step: Load the simulation PE file loader module

[0051] The second step: Load the X86 / X64 disassembly instruction parsing module

[0052] The third step: Load the general shell recognition and decryption data stream algorithm module

[0053] The fourth step: Load the PE file repair module

[0054] The fifth step: Load the file dump module

[0055] First, run the automated unpacking engine and then load the cloud shell rule library into memory. Then, read the file to be unpacked into memory and run it as a PE file. Parse the binary opcode instructions of the PE file running in the current memory through the X86 / X64 disassembly instruction parsing module, parse them into corresponding assembly instructions, and identify the logical and conditional relationships of the current instructions. The general shell recognition and decryption data flow algorithm module locates and identifies the decompression algorithm and shell decryption algorithm in the current disassembly. The recognition condition is based on the cloud shell rule library. If a feature matching the rule library is found, set a software breakpoint to interrupt at the current EIP pointer position where the match passes. Otherwise, use the general intelligent algorithm in the general shell recognition engine for location. If found, set a breakpoint. When the program interrupts after the current EIP, and the OEP position of the real unpacked file after decompression is repaired through the PE file repair module, then dump the repaired unpacked file to the local to save it as a new unpacked binary file and run it.

[0056] The X86 / X64 disassembly instruction parsing includes the following sub-modules: virtualized code fragment execution module, CPU instruction parsing module, and invisible breakpoint setting module. The virtualized code fragment execution module is mainly composed of binary opcodes virtualized into real CPU execution code fragments. The components are composed of binary bytecodes, all control flow, logical operation conditional statements, and polynomial floating-point operations including MMX multimedia operation instructions and 8087 oblique processing instructions, and are virtualized into assembly code. Operations such as removing junk instructions, SMC code, and restoring logically distorted and inflated code are performed on the current assembly instructions. The CPU instruction parsing module is composed of multiple binary code conversion conditions and a large number of opcode codes for recognition. The invisible breakpoint setting module consists of int3 software breakpoints and debug registers DR0 - DR3, which bypass the shell code with CRC checksums in the code segments in the shell respectively, so as to achieve the purpose of interrupting in different shell scenarios.

[0057] Emulated PE file loader module: file mapping to memory module, PE file format checking module, traversing PE file export table and import table module, reading tls resource relocation information module, PE file memory repair module. The file mapping to memory module loads the PE file after traffic restoration, calls the PE file format checking module, then calls the traversing PE file table and import module and the reading tls resource relocation information module, and then repairs all the obtained block information through the PE file memory repair module, and then calls the X86 / X64 disassembly instruction parsing module to perform opcode parsing on the file.

[0058] The functions of the general shell recognition and decryption data flow algorithm module include: decompression algorithm feature recognition module, dynamic memory quick scan module, software and hardware breakpoint setting module, and OEP distributed recognition module. The dynamic memory quick scan module is called to call the decompression algorithm feature recognition module to identify the code after the opcode parsing of the disassembly engine module, and then the software / hardware breakpoint setting module is called to set a breakpoint at the code position pointed to by the target's opcode algorithm feature EIP and let the program run to the breakpoint selected position, and then the OEP distributed recognition module is called to perform OEP entry distributed multi-point matching and path search on the decrypted post-code segment before shelling to track the OEP entry code of the real program.

[0059] The PE file repair module consists of: IAT repair module, tls relocation repair module, wherein after the OEP distributed identification module completes the identification of the decrypted oep code, the IAT repair module is called to identify the API function table called by the current target program after unpacking and repair the API function in the original input table, and then the tls relocation repair module is called to dynamically repair the base address relocation TLS position after unpacking to ensure that the program runs normally after unpacking.

[0060] The file dump module consists of: PE file dump module, segment reconstruction module, memory capture mirror module, new OEP calculation module. After the IAT repair module and tls relocation repair module are completed, the memory capture mirror module is called to perform full memory capture of the location from the image base address entry to the resource section in the PE memory, and then the PE file dump module is called to transfer it to the disk, and then the segment reconstruction module is called to add a new section to the current dump file after transfer to store the repaired IAT table code, and then the new OEP calculation module is called to fill the current image base address + virtual relative address = new OEP entry address into the local dump file, completing all the above unpacking operations and generating a new unpacked binary PE executable file.

[0061] The following is a specific example: The example of the malicious file automatic depacketization engine depacketizing Themida2.1.8

[0062] Sample background: A malicious automated sample that passed SDL risk control and stole the data

[0063] Analysis purpose: Extract traffic features and conduct behavior analysis on the risk control sample after de-shelling

[0064] Sample function: Bypass verification code by modifying the hardware information of the specified process

[0065] First, analyze the traffic and extract binary malicious sample files, such as Figure 3 As shown;

[0066] Detailed step 1: Load the shell feature library in the cloud as follows, as Figure 4 shown

[0067] Detailed step 2: Read the PE file into memory and execute it, as Figure 5 shown

[0068] Detailed step 3: Disassemble to identify shell features, as Figure 6 shown

[0069] Define the memory feature of the Themida shell header to identify the 0x35-length feature of the shell header:

[0070] 68 FF 6A 87 13 E8 FB 6F A6 FF 48 F7 D8 0F C8 3B CD 35 2C 62 B7 51 F9F7 C5 9D 30 4E 0A F7 D8 33

[0071] D8 F9 E9 E0 BE F0 FF 0F C8 35 98 68 E7 74 2D 4B 46 17 00 33 D8

[0072] Detailed step 4: Locate the position where the shell decrypts the real code: Locate it through the 8A 17 0F CF feature. As Figure 7 shown

[0073] Detailed step 5: Set breakpoints to decrypt the code before shelling

[0074] Search for the OEP feature of the code before shelling as follows: 33 FF 89 7D E4 33 C0 8B 5D 08 3B DF0F 95 C0 3B C7, and set breakpoints to interrupt the code at that position. As Figure 8 shown.

[0075] Detailed step 6: Apply for memory to copy the decrypted code to a new memory. The main purpose is to make a complete copy of the decrypted IAT table in a new memory for preparation when rebuilding the dump file.

[0076] Detailed step 7: Start to repair the PE code segment of the new memory image. As Figure 9 shown, in this case, there are several invalid IAT table functions that cannot be recognized, then the position of the API pointed to in the IAT address can be searched and interrupted through the disassembly engine

[0077] Detailed step 8: Dump the new memory image and save it to a local file.

[0078] After completing the above 8 steps, the TMD shell can be completely removed and the code can be analyzed without obstacles using IDA.

[0079] The Chinese explanations of the English abbreviations involved in this article are as follows:

[0080] Opcode instruction sequence, operation code. For example, if the opcode is push ebp / push rbp, then the opcode is 0x55.

[0081] EIP: In X86 / X64, it is collectively called the instruction pointer register, which is equivalent to pointing to the position of the current code executed by the CPU. For example: 16-bit assembly:

[0082] push bp

[0083] mov eb,sp

[0084] mov ax,0x16

[0085] add ax,0

[0086] mov al,0x8--->eip (the position pointed to)

[0087] mul ax,al

[0088] PE: The executable file structure that can be recognized by the operating system in win32 / win64.

[0089] dump: Grab a page of memory from the memory image and save it locally.

[0090] API: Standard interface functions exported by the system under windows / linux that can be called by application programs.

[0091] tls: Thread local storage corresponding to the current process (can be used for defining static variables in multithreading). Respectively, it can be used:

[0092] TlsAlloc allocates thread local storage space;

[0093] TlsFree releases thread local storage space;

[0094] TlsGetValue obtains the value in the thread local storage space;

[0095] TlsSetValue sets the value in the thread local storage space.

[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An implementation method of an automated unpacking engine for malicious files, characterized in that, It includes the following steps: Step S1, load the cloud shell rule library; Step S2, read the binary stream of the PE file into memory and execute it; Step S3, the disassembly instruction parsing module identifies specific shell features and the shell decompression location; Step S4, locate the decryption code position of the specific shell feature, set breakpoints and decrypt the code of the file before shelling; Step S5, apply for memory and copy the decrypted code segment to a new memory space; Step S6, repair the PE code segment in the new memory space; Step S7, use the file dump module to dump the PE code segment in the new memory space and save it as an image to a local file; In step S4, first, the general shell recognition and decryption data stream algorithm module locates and identifies the decompression algorithm and the shell decryption algorithm in the current disassembly. The recognition conditions are based on the cloud shell rule library. If features matching the rule library are found, set software breakpoints or hardware execution breakpoints, set breakpoints at the code position pointed to by the opcode algorithm feature EIP of the target, and let the program run to the breakpoint selected position; Next, call the OEP decentralized recognition module to perform decentralized multi-point matching of the OEP entry before shelling on the decrypted code segment, and trace the true OEP entry code of the program through the path search method; The file dump module described in step S7 includes a PE file dump module, a section reconstruction module, an inner layer capture image module, and a new OEP calculation module. When the IAT repair module and the tls relocation repair module complete the repair, call the memory capture image module to perform a full memory capture of the position from the image base address entry to the resource section in the PE memory, then call the PE file dump module to save it to disk, and then call the section reconstruction module to add a new section to the current dumped file to store the repaired IAT table code after the dump, and call the new OEP calculation module to add the virtual relative address to the current image base address, and fill the obtained new OEP entry address into the local dump file to complete all the unpacking operations and generate a new unpacked binary PE executable file; In step S6, call the IAT repair module to identify and repair the API function table called by the target program after unpacking the current shell, and then call the tls relocation repair module to dynamically repair the base address relocation TLS position after unpacking to ensure the normal operation of the program after unpacking.

2. The method for implementing an automated unpacking engine for malicious files according to claim 1, wherein: The specific steps of step S2 include: First, read the binary stream of the PE file through the emulated PE loader and map it to memory; Then, locate the target block information of the PE file by judging the PE header file format structure features; Next, traverse the import / export table, read the tls resource relocation information, and repair the obtained block information through the PE file memory repair module.

3. The implementation method of the automated unpacking engine for malicious files according to claim 1, wherein: The specific content of step S3 includes: First, the disassembly instruction parsing module parses the current opcode code in memory into the corresponding X86 or X64 assembly code; Then, the general shell recognition and decryption data stream algorithm module dynamically identifies specific shell features and the shell decompression location.

Citation Information

Patent Citations

  • Automatic analyzing system and method for dynamic action of malicious program

    CN101154258A

  • Confusing method and device of executable application

    CN104573426A