You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于Mirai恶意软件toggle_obf函数XOR加解密逻辑的技术咨询:如何将\x22\x35转换为23

关于Mirai恶意软件toggle_obf函数XOR加解密逻辑的技术咨询:如何将\x22\x35转换为23

Hey there, let's break this down step by step so you can see exactly how that \x22\x35 turns into 23 after running through toggle_obf. I’ve dug into Mirai’s obfuscation logic a bunch, so this should make sense once we unpack it.

First, let's simplify the toggle_obf function's XOR logic—those four consecutive XORs on each byte can be collapsed into a single operation, thanks to XOR's mathematical properties (it's associative and commutative, meaning the order doesn't matter, and XORing a value with itself cancels out).

The table_key is 0xdeadbeef, so let's split it into its four individual bytes:

k1 = 0xef  // 0xdeadbeef & 0xff
k2 = 0xbe  // (0xdeadbeef >> 8) & 0xff
k3 = 0xad  // (0xdeadbeef >> 16) & 0xff
k4 = 0xde  // (0xdeadbeef >> 24) & 0xff

Now calculate the cumulative XOR of these four bytes—this is the equivalent key each byte gets XORed with in one step:

0xef ^ 0xbe = 0x51
0x51 ^ 0xad = 0xfc
0xfc ^ 0xde = 0x22

So every byte in the entry is effectively XORed with 0x22 when toggle_obf runs.

Next, let's look at the encrypted entry \x22\x35—that's two bytes: 0x22 and 0x35. Since toggle_obf is self-inverting (running it twice reverts the bytes to their original state), decrypting just means applying that same 0x22 XOR to each byte:

  • First byte: 0x22 ^ 0x22 = 0x00
  • Second byte: 0x35 ^ 0x22 = 0x17

Now, TABLE_CNC_PORT is a 16-bit network port, which Mirai stores in big-endian byte order (most significant byte first). Putting those two decrypted bytes together gives us 0x0017—which is 23 in decimal. That's exactly the comment's reference!

To confirm we got this right, let's reverse the process: take the plaintext port 23 (which is 0x0017 in big-endian 16-bit form) and apply the XOR with 0x22 per byte:

  • 0x00 ^ 0x22 = 0x22
  • 0x17 ^ 0x22 = 0x35
    Which matches the encrypted \x22\x35 in the code perfectly.

Key takeaways to solidify your understanding:

  • The four separate XOR calls in toggle_obf are a bit of a red herring—they reduce to a single XOR with the cumulative key 0x22 for this specific table_key value
  • Mirai uses this routine to toggle obfuscation on sensitive values (like C2 ports); running the function switches between plaintext and ciphertext
  • The port entry uses big-endian ordering, so the decrypted bytes 0x00 + 0x17 translate directly to the decimal port number 23

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.08 09:33:01