Skip to content

Profile Encoding

Profile Encoding Techniques

Encoding C2 commands is a critical step in designing malleable C2 profiles. By obfuscating payloads, operators can evade signature-based detection, bypass network filters, and ensure data integrity during transmission. This section explores three common encoding techniques: Base64, XOR, and custom serialization formats.


Base6

Base64 encoding converts binary data into ASCII text by representing 6-bit chunks as printable characters. It is widely used for embedding binary data in text-based protocols (e.g., HTTP, JSON) and is often combined with other obfuscation methods.

Example: Base64 Encoding in Python

import base64

# Encode a payload
payload = b"GET /secret/path HTTP/1.1\r\nHost: target.com\r\n"
encoded = base64.b64encode(payload).decode('utf-8')
print("Encoded:", encoded)

# Decode back to original
decoded = base64.b64decode(encoded).decode('utf-8')
print("Decoded:", decoded)

Use Cases

  • Embedding binary payloads in JSON/HTTP requests.
  • Combining with XOR for layered obfuscation.

Limitations

  • Base64 is easily detectable via signature analysis.
  • Requires careful handling of padding (= characters) in encoded data.

XOR Encoding

XOR (exclusive OR) is a bitwise operation that toggles bits between two values. It is often used for simple obfuscation, as it is reversible with the same key.

Example: XOR Encoding in Python

def xor_encode(data, key):
    return ''.join([chr(ord(c) ^ ord(key)) for c in data])

def xor_decode(data, key):
    return xor_encode(data, key)  # XOR is its own inverse

# Example usage
key = "X"
payload = "C2CommandHere"
encoded = xor_encode(payload, key)
print("Encoded:", encoded)
decoded = xor_decode(encoded, key)
print("Decoded:", decoded)

Use Cases

  • Quick obfuscation of small payloads.
  • Integration with steganographic techniques (e.g., hiding XORed data in image files).

Limitations

  • Weak security if the key is static or short.
  • Requires careful key management to avoid exposure.

Custom Serialization Formats

Custom serialization formats allow operators to define proprietary structures for encoding C2 commands. These formats often include headers, checksums, and versioning fields to evade pattern-based detection.

Example: Custom Binary Format

import struct

# Define a simple format: 4-byte magic number + 2-byte length + payload
def serialize(data):
    magic = b"\x01\x02\x03\x04"
    length = len(data)
    return magic + struct.pack("<H", length) + data

def deserialize(data):
    if data.startswith(b"\x01\x02\x03\x04"):
        length = struct.unpack("<H", data[4:6])[0]
        payload = data[6:6+length]
        return payload
    return None

# Example usage
payload = b"SecretCommand"
encoded = serialize(payload)
print("Encoded:", encoded)
decoded = deserialize(encoded)
print("Decoded:", decoded)

Key Design Considerations

  • Magic numbers: Unique identifiers to detect custom payloads.
  • Checksums: Ensure data integrity during transmission.
  • Versioning: Support backward compatibility for evolving C2 profiles.

Key takeaways

  • Base64 is ideal for simple text-based encoding but lacks security.
  • XOR provides lightweight obfuscation but requires secure key management.
  • Custom formats offer flexibility and evasion capabilities but demand careful design and implementation.