Skip to content

Obfscura

Warning

This is an advanced topic

Obfscura - the ‘F’ is silent.

Obfscura is our in-house PE packer, mutator, and virtualizer.

Packing

By leveraging the latest compression algorithms and our in-house reflective PE loader it is possible to reduce the PE size while destroying a lot of the original PE information. This completely hides the original PE from all on disk scanners and most in memory scanners.

Mutation

Due to anti-cheats frequently employing not only checksum/hash checks, but also looking for signatures, it is necessary for code to be unique every time it is executed.

The following describes the core of Obfscura functionality:

  • Load a given PE.
  • Decompile and analyze all the functions, code paths, data, and attributes of a PE.
  • Use a our in-house mutation engine powered by the iced disassembler and assembler to mutate every single assembly instruction.
  • Recompile the entire program.

The output of this process is something akin to other more well-known mutators such VMProtect and Themida.

The breakthrough - by using custom tooling to bypass the extremely heavy LLVM we are able to mutate multi-gigabyte PE files in just seconds. Allowing for on-the-fly mutation on every download from the Warp website.

Virtualization

All conventional reverse engineering tooling relies on a safe assumption - all desktop CPUs execute the exact same standard set of assembly instructions commonly known as x86-64.

Virtualization breaks this assumption.

Code virtualization involves creating a Virtual Machine (aka VM) that uses a different architechture and/or set of (often randomized) assembly instructions.