A team of security researchers from Deep Instinct has discovered a method to insert malware inside a digitally signed binary without affecting the overall hash of the file, which almost ensures that antivirus and security software will not detect the malicious file.
When users double-click an executable and it launches, Windows does three things. First, it reads the PE (Portable Executable) headers of the file, then it validates the certificate, and finally it validates the hash of the file.
After reverse-engineering this entire process, the Deep Instinct team discovered that Windows does not include three levels from the PE headers, during the validation process, to the file hash validation, and that modifying these three pieces does not destroy the validity of the certificate.
The fields are the file's Checksum, the attribute certificate table, and the IMAGE_DIRECTORY_ENTRY_SECURITY field from the DataDirectory section.
In the proof-of-concept code, which they did not reveal for obvious reasons, the research team inserted malicious code into the attribute certificate table, successfully leaving the digital certificate and file hash intact.
This method is so effective that malware developers don't even need to hide their malicious code through packers (code obfuscators). The reason is that antivirus and security software automatically ignore any digital signature of the file.
This technique, by leaving the file hash intact, also bypasses any other secondary security software checks that may be performed, other than the check for a digital certificate.
The researchers also circumvented the problem of not being able to execute malicious code from a file's attribute certificate table, which is present in the file's digital certificate.
“Having a malicious file on disk without having to recognize it is easy, but it has nothing to do with whether you make it interesting,” the research team explained in their recent Black Hat presentation . “That’s why we created a Reflective PE Loader: To execute PE files directly from memory.”
Despite their success, the Deep Instinct team said that their Reflective PE Loader does not support 64-bit architectures, at least for now.
For malware writers, the Deep Instinct team's research is the gospel of malware programming, providing the ideal method of hiding malicious code in plain sight, right inside the digital certificate, the part of the file that is supposed to validate a file's origin and protect users from malware.


