Obfscura
Warning
This is an advanced topic
Obfscura - the ‘F’ is silent.
Obfscura is our in-house PE packer, mutator, and virtualizer.
Packing
By leveraging the latest compression algorithms and our in-house reflective PE loader it is possible to reduce the PE size while destroying a lot of the original PE information. This completely hides the original PE from all on disk scanners and most in memory scanners.
Mutation
Due to anti-cheats frequently employing not only checksum/hash checks, but also looking for signatures, it is necessary for code to be unique every time it is executed.
The following describes the core of Obfscura functionality:
- Load a given PE.
- Decompile and analyze all the functions, code paths, data, and attributes of a PE.
- Use a our in-house mutation engine powered by the iced disassembler and assembler to mutate every single assembly instruction.
- Recompile the entire program.
The output of this process is something akin to other more well-known mutators such VMProtect and Themida.
The breakthrough - by using custom tooling to bypass the extremely heavy LLVM we are able to mutate multi-gigabyte PE files in just seconds. Allowing for on-the-fly mutation on every download from the Warp website.
Virtualization
All conventional reverse engineering tooling relies on a safe assumption - all desktop CPUs execute the exact same standard set of assembly instructions commonly known as x86-64.
Virtualization breaks this assumption.
Code virtualization involves creating a Virtual Machine (aka VM) that uses a different architechture and/or set of (often randomized) assembly instructions.