Lazy RC4: Payload Encryption Using SystemFunction032
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要特定的开头。我得先仔细阅读文章内容,了解主要讲的是什么。 文章开头提到作者周末写恶意软件时想到如何在代码中实现RC4加密。接着他介绍了传统的RC4实现比较长,占用代码空间较大。然后他找到了一个Windows的 undocumented API,SystemFunction032,这个API可以内部实现RC4加密。 文章详细讲解了如何使用这个API,包括USTRING结构、函数原型以及如何编写一个RC4加密的辅助函数。还给出了一个示例代码,展示了如何用这个API来加密和解密数据。 最后,作者总结了这种方法的优势:避免手动实现RC4,使代码更紧凑,并适用于壳代码加密、负载混淆等场景。 所以,总结起来,这篇文章主要介绍了如何利用Windows的SystemFunction032 API来实现RC4加密,避免了手动编写复杂的代码,并提供了具体的实现方法和示例。 </think> 文章介绍了一种通过Windows undocumented API SystemFunction032实现RC4加密的方法。该API位于Advapi32.dll中,支持直接对缓冲区进行RC4加密和解密操作。文章提供了使用该API的示例代码,并说明其适用于壳代码加密、负载混淆等场景。 2026-4-15 05:58:58 Author: infosecwriteups.com(查看原文) 阅读量:10 收藏

Itz.sanskarr

Press enter or click to view image in full size

Photo by Gabriela on Unsplash

It’s the weekend and I was writing malware for fun. A thought popped into my mind: what are the other ways we can implement RC4 in our code to encrypt a payload? So here is a short article on it.

The classic RC4 implementation is fairly long. It usually includes key scheduling, permutation arrays, and additional logic that increases code size. It works, but it is not always ideal when you want something compact for payload encryption. While searching for alternative approaches, I came across an undocumented Windows API called SystemFunction032, exported by Advapi32.dll, which already implements RC4 internally.

This means we can use the Windows API directly instead of implementing RC4 ourselves.

What is SystemFunction032

SystemFunction032 is an undocumented Windows function that performs RC4 encryption directly on a buffer. Since RC4 is symmetric, the same function is used for both encryption and decryption.

Get Itz.sanskarr’s stories in your inbox

Join Medium for free to get updates from this writer.

Remember me for faster sign in

The function expects two USTRING structures:

  • One describing the data buffer
  • One describing the key buffer

The data buffer is modified in place by the function.

The USTRING Structure

typedef struct {
DWORD Length;
DWORD MaximumLength;
PVOID Buffer;
} USTRING;

This structure describes a buffer in memory:

  • Buffer points to the data
  • Length specifies how much data to process
  • MaximumLength defines the buffer capacity

Function Prototype

We dynamically resolve the function from Advapi32.dll:

typedef NTSTATUS (WINAPI* fnSystemFunction032)(
USTRING* Data,
USTRING* Key
);

The encryption happens in place, meaning the original buffer gets modified directly.

RC4 Helper Using SystemFunction032

#include <windows.h>
#include <stdio.h>

typedef struct {
DWORD Length;
DWORD MaximumLength;
PVOID Buffer;
} USTRING;
typedef NTSTATUS (WINAPI* fnSystemFunction032)(
USTRING* Data,
USTRING* Key
);
BOOL Rc4EncryptionViaSystemFunc032(
PBYTE pRc4Key,
PBYTE pPayloadData,
DWORD sRc4KeySize,
DWORD sPayloadSize
) {
USTRING Data = { sPayloadSize, sPayloadSize, pPayloadData };
USTRING Key = { sRc4KeySize, sRc4KeySize, pRc4Key };
fnSystemFunction032 SystemFunction032 =
(fnSystemFunction032)GetProcAddress(
LoadLibraryA("Advapi32.dll"),
"SystemFunction032"
);
return SystemFunction032(&Data, &Key) == 0;
}

Using It to Encrypt a Payload

int main() {
BYTE data[] = "HelloWorld";
BYTE key[] = "secretkey";
DWORD dataSize = sizeof(data) - 1;
DWORD keySize = sizeof(key) - 1;
printf("Original: %s\n", data);
Rc4EncryptionViaSystemFunc032(key, data, keySize, dataSize);
printf("Encrypted: ");
for (int i = 0; i < dataSize; i++)
printf("%02X ", data[i]);
printf("\n");
Rc4EncryptionViaSystemFunc032(key, data, keySize, dataSize);
printf("Decrypted: %s\n", data);
return 0;
}

Example output:

Original: HelloWorld
Encrypted: A1 3F 9C 22 11 7B 8E 44 29 90
Decrypted: HelloWorld

Why This Works

RC4 is a symmetric stream cipher. Encryption and decryption are identical operations. Calling the function twice with the same key restores the original buffer.

Use Cases for Payload Encryption

This approach is useful for:

  • shellcode encryption
  • payload obfuscation
  • runtime decryption
  • encrypted configuration blobs
  • loader development

Typical workflow:

  1. Encrypt payload
  2. Store encrypted bytes
  3. Decrypt at runtime
  4. Execute payload

Final Note

Using SystemFunction032 avoids implementing RC4 manually and keeps the code compact. The API already handles the algorithm internally, and we only need to wrap our buffers using USTRING and call the function. This makes it a clean and practical approach for payload encryption.

That’s it for this short article. Enjoy yourself.


文章来源: https://infosecwriteups.com/lazy-rc4-payload-encryption-using-systemfunction032-9b89c370f407?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh