Malware

Obfuscation

Obfuscation is writing code so a human cannot easily read it while a machine still runs it. Attackers use it to hide malware from scanners and reviewers, and some honest vendors use it to protect their source.

How it is measured

Signals are structural: very long single lines, string arrays with index lookups, hex or unicode escapes in every string, variable names like _0x4f2a, nested eval or Function calls, and long base64 blobs. One enormous line in a theme file is worth a look on its own.

To see what the code does, deobfuscate in a safe environment: format it, decode the strings, and run it in a sandbox or a Node VM with the network blocked, logging what it calls. Do not run unknown code on a machine that holds credentials.

Worked example

A cleanup on a small law firm's WordPress site finds functions.php ending with a single 41 KB line: an array named _0x1a2b full of hex-escaped strings, followed by a loop that rotates the array. After formatting and rotating, the decoded strings spell out a script URL, 'createElement', and 'appendChild'.

The 41 KB is a loader that injects a remote script into every page. The theme developer's real code was 2 KB above it. Neither the line length nor the dull file name made it look suspicious in the editor; the array-rotate pattern did.

How it differs

A packer compresses or wraps code so it unpacks at runtime, often as an obfuscation layer. Obfuscation is the broader goal of making code hard to read, which can be done with renaming, string encoding, and control-flow tricks and no unpacking stub. Packed code is always hard to read; obfuscated code is not always packed.

Common errors

Treating all minified code as malicious; minification drops whitespace and shortens names but hides no logic. Assuming obfuscated means infected. Searching only for the word eval. Running the decoded script on a live machine to see what happens. Cleaning the loader and missing the second copy in the database.

In practice

Record known minified vendor files by path and hash, so unexplained obfuscated code in themes, mu-plugins, or uploads stands out. When you find some, decode it offline, note the domains and file paths it touches, and search the rest of the site and database for the same strings.

See also

Packer, Eval atob

Sources

Count this on a real site.

Watch my website