Skip to content

Resolving API Calls

Malware often employs obfuscation techniques like indirect API calls or encryption to evade detection. Resolving these calls is critical for understanding the true behavior of malicious code. Ghidra provides tools to analyze and resolve indirect API calls, even in obfuscated binaries, enabling analysts to identify suspicious or malicious function invocations.


Using Ghidra's API Resolver Plugin

Ghidra’s API Resolver plugin automates the process of resolving indirect API calls by cross-referencing hashes or encrypted values against known API tables.

Steps to Enable and Use the Plugin

  1. Install the Plugin:
  2. Navigate to Tools > Plugins and ensure the API Resolver plugin is enabled.
  3. If not available, download and install it from the Ghidra GitHub repository.

  4. Analyze Call Sites:

  5. Right-click a function in the Decompiled View and select "Analyze All Call Sites".
  6. Ghidra will resolve indirect calls (e.g., Call to [0x401000]) by matching the target address to known API tables (e.g., LoadLibraryA, GetProcAddress).

  7. Example:

    // Obfuscated call using a hash (e.g., API hash for CreateFileA)
    void (*func)(...) = (void (*)(...))0x401000;
    func(...);
    
    Ghidra will resolve 0x401000 to CreateFileA if the hash matches known API entries.


Analyzing Indirect Call Sites

Obfuscated code often uses indirect jumps or pointers to API functions. Ghidra’s Call Graph and Function Signatures features help identify these patterns.

Identifying Indirect Calls

  1. Search for Call Instructions:
    Use the Search tool to find Call instructions with immediate operands (e.g., Call 0x401000).

    # Example Ghidra search query for indirect calls
    Call *0x[0-9A-F]+
    

  2. Check for API Hashes:
    Obfuscated code may store API hashes (e.g., 0x56A5F4E2) in memory. Use the Memory Viewer to inspect these values and cross-reference them with known API hashes.

  3. Example:

    ; Encrypted API call (e.g., XORed hash for VirtualProtect)
    mov eax, [0x402000]   ; Load encrypted hash
    xor eax, 0x12345678   ; Decrypt hash
    call eax             ; Indirect call to VirtualProtect
    
    Ghidra can flag this as a potential API call if the decrypted hash matches a known API.


Identifying Malicious API Calls

Once resolved, analyze the API names and their combinations for suspicious behavior. Common malicious patterns include:
- File operations: CreateFileA, WriteFile, DeleteFileA
- Process injection: VirtualAlloc, VirtualProtect, CreateRemoteThread
- Network activity: WSASocketA, send, recv
- Persistence: RegCreateKeyExA, CreateServiceA

Example Workflow

  1. Resolve all API calls using the API Resolver plugin.
  2. Filter results to suspicious functions (e.g., CreateFileA with WriteFile).
  3. Cross-reference resolved APIs with threat intelligence databases (e.g., VirusTotal, AlienVault OTX).

Key takeaways

  • Use Ghidra’s API Resolver plugin to automate the resolution of indirect API calls.
  • Analyze indirect call sites and API hashes to uncover obfuscated malicious behavior.
  • Combine resolved API names with threat intelligence to identify known malicious patterns.
  • Manual inspection is critical for advanced obfuscation (e.g., encrypted API hashes).
  • Focus on suspicious API combinations (e.g., file I/O + process injection) for potential malware detection.