本文へ移動
cccskills
無料GitHub で公開

resolving-dynamic-api-hashing

Resolves dynamically hashed Windows API names by brute-forcing observed hash constants against a wordlist of API/DLL names using common malware hashing algorithms (ROR13, djb2, FNV, CRC32). Activates for requests to resolve API hashes, identify hashed imports, or reverse an API hashing routine.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md2.6 KB
  • LICENSE340 B
  • references/api-reference.md1.2 KB
  • scripts/analyst.py3.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Resolving Dynamic API Hashing

When to Use

  • A sample resolves APIs by hash (no plaintext import names) and you have the hash constants from disassembly.
  • You need to map each hash back to an API/DLL name to understand functionality.

Do not use this to execute the resolver — it computes hashes over a name wordlist statically and matches them to your observed constants.

Prerequisites

  • The hash constants observed in the binary and (optionally) a names wordlist.

Workflow

Step 1: Identify the algorithm

python scripts/analyst.py id 0x6A4ABC5B

Computes the constant under each supported algorithm against a built-in seed list to suggest which algorithm/seed reproduces known API hashes.

Step 2: Resolve hashes against a wordlist

python scripts/analyst.py resolve hashes.txt --algo ror13 --wordlist names.txt

Brute-forces the provided hashes against the wordlist using the chosen algorithm and reports matches.

Step 3: Annotate the disassembly

Label resolved call sites with their API names to recover behavior.

Step 4: Document the routine

Record the algorithm, seed/initial value, and any key so the routine is reusable.

Validation

  • The chosen algorithm reproduces at least one known API hash (sanity anchor).
  • Resolved names are real exported symbols of plausible DLLs.
  • Unresolved hashes are reported, not silently dropped.

Pitfalls

  • Wrong endianness/rotation direction producing no matches — try variants.
  • Algorithms seeded with a per-sample key; without the key, matches fail.
  • Case sensitivity: some routines hash uppercased names, others as-is.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する