Dynamic API Resolution

T1027.007

Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org

About this technique

Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various Native API functions provided by the OS to perform various tasks such as those involving processes, files, and other system artifacts.

API functions called by malware may leave static artifacts such as strings in payload files. Defensive analysts may also uncover which functions a binary file may execute via an import address table (IAT) or other structures that help dynamically link calling code to the shared modules that provide functions.

To avoid static or other defensive analysis, adversaries may use dynamic API resolution to conceal malware characteristics and functionalities. Similar to Software Packing, dynamic API resolution may change file signatures and obfuscate malicious API function calls until they are resolved and invoked during runtime.

Various methods may be used to obfuscate malware calls to API functions. For example, hashes of function names are commonly stored in malware in lieu of literal strings. Malware can use these hashes (or other identifiers) to manually reproduce the linking and loading process using functions such as `GetProcAddress()` and `LoadLibrary()`. These hashes/identifiers can also be further obfuscated using encryption or other string manipulation tricks (requiring various forms of Deobfuscate/Decode Files or Information during execution).

Detection rules0

Rules on DetectionCode tagged with T1027.007.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups3

Software17

Campaigns0

None recorded.

Procedure examples20

Groups3

Used byProcedure example
GroupKimsuky

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.

GroupLazarus Group

Lazarus Group has used a custom hashing method to resolve APIs used in shellcode.

GroupMustang Panda

Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

Software17

Used byProcedure example
MalwareAvosLocker

AvosLocker has used obfuscated API calls that are retrieved by their checksums.

MalwareBazar

Bazar can hash then resolve API calls at runtime.

ToolBrute Ratel C4

Brute Ratel C4 can call and dynamically resolve hashed APIs.

MalwareCANONSTAGER

CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used.

MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use `LoadLibrary` and `GetProcAddress` to resolve Windows API function strings at run time.

MalwareCLAIMLOADER

CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically.

MalwareHiddenFace

HiddenFace can dynamically resolve Windows APIs.

MalwareHTTPTroy

HTTPTroy has utilized dynamic API resolution by reconstructing API calls during runtime using combinations of arithmetic and logical operations to complicate static analysis.

View all 17 software examples

References4

  1. BlackHat API Packers Open source
    Choi, S. (2015, August 6). Obfuscated API Functions in Modern Packers. Retrieved August 22, 2022.
  2. Drakonia HInvoke Open source
    drakonia. (2022, August 10). HInvoke and avoiding PInvoke. Retrieved August 22, 2022.
  3. Huntress API Hash Open source
    Brennan, M. (2022, February 16). Hackers No Hashing: Randomizing API Hashes to Evade Cobalt Strike Shellcode Detection. Retrieved August 22, 2022.
  4. IRED API Hashing Open source
    spotheplanet. (n.d.). Windows API Hashing in Malware. Retrieved August 22, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.