x64 Architecture
x64 Architecture and Modern Techniques¶
Modern malware leverages advanced x64 architecture features to evade detection, obscure execution logic, and execute malicious payloads. This section covers critical concepts like x64 calling conventions, RIP-relative addressing, and advanced control flow techniques commonly used in malware analysis.
x64 Calling Conventions¶
The x64 calling convention defines how functions pass arguments, return values, and manage the stack. Key aspects include:
- Register Usage: The first four integer/pointer arguments are passed via
RCX,RDX,R8, andR9. Floating-point arguments useXMM0–XMM3. - Return Value: The result of a function is stored in
RAX(integer/pointer) orXMM0(floating-point). - Stack Alignment: The caller ensures the stack is 16-byte aligned before calling a function.
- Callee-Saved Registers: Registers like
RBX,RBP,R12–R15must be preserved by the callee.
Example:
; Function call in x64
mov rcx, 0x42 ; First argument
call my_function ; my_function receives RCX as its first parameter
Analysis Tip: Use Ghidra’s "Function" view to identify calling conventions and track register usage during reverse engineering.
RIP-Relative Addressing¶
RIP-relative addressing allows position-independent code (PIC), which is critical for malware to avoid detection. Instead of absolute addresses, offsets are calculated relative to the RIP (Instruction Pointer) register.
- Mechanism: Instructions like
LEAorJMPuseRIP + displacementto compute addresses. - Malware Use Cases:
- Code Injection: Malware can inject code into memory without relying on fixed addresses.
- Polymorphism: Encrypted payloads use RIP-relative jumps to decode themselves at runtime.
Example:
; RIP-relative jump (e.g., in a polymorphic payload)
lea rax, [rip + 0x10] ; Load address of instruction 0x10 bytes ahead
jmp rax ; Jump to the computed address
Analysis Tip: Look for RIP-based offsets in Ghidra’s disassembly to identify obfuscated control flow or encrypted payloads.
Advanced Control Flow Techniques¶
Malware often employs sophisticated control flow techniques to evade static analysis and sandbox detection:
- Indirect Jumps:
- Use registers or memory to determine the target address (e.g.,
jmp [rax]). -
Example:
-
Jump Tables:
- Arrays of addresses used to route execution dynamically.
-
Example:
-
Control Flow Flattening:
- Merge all branches into a single structure, using a dispatcher to select the next step.
-
Example:
-
Return-Oriented Programming (ROP):
- Chain together "gadgets" (short instruction sequences) to execute arbitrary code without direct
CALL/JMP. - Example:
Analysis Tip: Ghidra’s "Graph View" can help visualize control flow flattening, while ROP chains often require manual reconstruction of gadget sequences.
Key takeaways¶
- x64 calling conventions use registers for arguments and
RAXfor return values, requiring careful analysis of register usage. - RIP-relative addressing enables position-independent code, critical for malware evasion and polymorphism.
- Advanced control flow techniques like indirect jumps, jump tables, and ROP are common in malware to obfuscate execution paths.
- Tools like Ghidra are essential for analyzing these techniques, especially when combined with dynamic analysis and code reconstruction.