关于Mirai恶意软件toggle_obf函数XOR加解密逻辑的技术咨询:如何将\x22\x35转换为23
Hey there, let's break this down step by step so you can see exactly how that \x22\x35 turns into 23 after running through toggle_obf. I’ve dug into Mirai’s obfuscation logic a bunch, so this should make sense once we unpack it.
First, let's simplify the toggle_obf function's XOR logic—those four consecutive XORs on each byte can be collapsed into a single operation, thanks to XOR's mathematical properties (it's associative and commutative, meaning the order doesn't matter, and XORing a value with itself cancels out).
The table_key is 0xdeadbeef, so let's split it into its four individual bytes:
k1 = 0xef // 0xdeadbeef & 0xff k2 = 0xbe // (0xdeadbeef >> 8) & 0xff k3 = 0xad // (0xdeadbeef >> 16) & 0xff k4 = 0xde // (0xdeadbeef >> 24) & 0xff
Now calculate the cumulative XOR of these four bytes—this is the equivalent key each byte gets XORed with in one step:
0xef ^ 0xbe = 0x51 0x51 ^ 0xad = 0xfc 0xfc ^ 0xde = 0x22
So every byte in the entry is effectively XORed with 0x22 when toggle_obf runs.
Next, let's look at the encrypted entry \x22\x35—that's two bytes: 0x22 and 0x35. Since toggle_obf is self-inverting (running it twice reverts the bytes to their original state), decrypting just means applying that same 0x22 XOR to each byte:
- First byte:
0x22 ^ 0x22 = 0x00 - Second byte:
0x35 ^ 0x22 = 0x17
Now, TABLE_CNC_PORT is a 16-bit network port, which Mirai stores in big-endian byte order (most significant byte first). Putting those two decrypted bytes together gives us 0x0017—which is 23 in decimal. That's exactly the comment's reference!
To confirm we got this right, let's reverse the process: take the plaintext port 23 (which is 0x0017 in big-endian 16-bit form) and apply the XOR with 0x22 per byte:
0x00 ^ 0x22 = 0x220x17 ^ 0x22 = 0x35
Which matches the encrypted\x22\x35in the code perfectly.
Key takeaways to solidify your understanding:
- The four separate XOR calls in
toggle_obfare a bit of a red herring—they reduce to a single XOR with the cumulative key0x22for this specifictable_keyvalue - Mirai uses this routine to toggle obfuscation on sensitive values (like C2 ports); running the function switches between plaintext and ciphertext
- The port entry uses big-endian ordering, so the decrypted bytes
0x00+0x17translate directly to the decimal port number 23
内容来源于stack exchange

