[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRAkSV9eqsSTT68RxziHggH7vsfsoP1bS8sgt-kvLcZA":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},212,"How does Braille Pattern obfuscation work according to the article?","Braille Patterns consist of 64 distinct patterns mapped to 256 Unicode positions. In the obfuscation method described, each character to be hidden is first converted to its Unicode code, then transformed into a Braille symbol using either single or double Braille characters. For example, lowercase letters use a single Braille code, while uppercase letters and digits use two Braille characters with a fixed prefix (U2820 for uppercase, U283C for digits). The article notes that the mapping can be randomized to increase the difficulty of analysis, deviating from standard Braille grade 1 rules.","\u003Cp>Braille Patterns consist of 64 distinct patterns mapped to 256 Unicode positions. In the obfuscation method described, each character to be hidden is first converted to its Unicode code, then transformed into a Braille symbol using either single or double Braille characters. For example, lowercase letters use a single Braille code, while uppercase letters and digits use two Braille characters with a fixed prefix (U2820 for uppercase, U283C for digits). The article notes that the mapping can be randomized to increase the difficulty of analysis, deviating from standard Braille grade 1 rules.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-obfuscating-strings-using-unicode-encoding\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-braille-pattern-obfuscation-work-according-to-the-article-1777484635497","Braille Patterns, Unicode mapping, character obfuscation, encoding scheme",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},55,"Penetration Basics - Obfuscating Strings Using Unicode Encoding","penetration-basics-obfuscating-strings-using-unicode-encoding","Learn how to obfuscate strings using Unicode Braille Patterns to evade static detection in penetration testing. Includes encoding\u002Fdecoding methods and implementation.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, critical code (such as shellcode) is often obfuscated to evade static detection and analysis.\u003C\u002Fp>\u003Cp>I recently encountered an interesting sample that uses Braille Patterns to obfuscate strings, posing significant challenges for static analysis.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018744999_0_216e3b210f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018750664_1_9787367b48.png\">\u003C\u002Fp>\u003Cp>Sample address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Ffile\u002F06f90a471f65de9f9805a9e907d365a04f4ebed1bf28b458397ad19afdb9ac00\u002Fdetection\u003C\u002Fp>\u003Cp>This article will introduce this method of obfuscating strings using Unicode encoding. It will cover implementing encoding and decoding for Braille Patterns through programs and share ideas for using other Unicode character tables for encoding and decoding.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation principles of the sample characters\u003C\u002Fli>\u003Cli>Encoding via program\u003C\u002Fli>\u003Cli>Decoding via program\u003C\u002Fli>\u003Cli>Approach to encoding and decoding using other Unicode character tables\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation principle of sample characters\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Basic Knowledge 1: Unicode\u003C\u002Fh3>\u003Cp>Unicode is an encoding scheme developed to overcome the limitations of traditional character encoding methods. It assigns a uniform and unique binary code to each character in every language, meeting the requirements for cross-language and cross-platform text conversion and processing.\u003C\u002Fp>\u003Cp>Simple understanding: Every character we see on a computer corresponds to a unique Unicode code.\u003C\u002Fp>\u003Cp>Applying this to the sample mentioned above, although Braille Patterns are used to create difficulty for manual analysis, converting each character into its Unicode code can overcome this problem.\u003C\u002Fp>\u003Ch3>Basic Knowledge 2: Braille Patterns\u003C\u002Fh3>\u003Cp>These are specialized text symbols designed for blind people to read by touch and write.\u003C\u002Fp>\u003Cp>Braille consists of 64 distinct patterns, meaning each character has 64 possible styles.\u003C\u002Fp>\u003Cp>Braille Patterns occupy 256 positions in the Unicode table, meaning there are 256 Unicode codes corresponding to Braille Patterns.\u003C\u002Fp>\u003Cp>To support more characters, the following method is used in the correspondence:\u003C\u002Fp>\u003Cul>\u003Cli>Lowercase English letters correspond to single Unicode codes\u003C\u002Fli>\u003Cli>Arabic numerals correspond to two Unicode codes, with the first Unicode code fixed at U283C\u003C\u002Fli>\u003Cli>Uppercase English letters correspond to two Unicode codes, with the first Unicode code fixed at U2820\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Lowercase English letters also correspond to two Unicode codes, with the first Unicode code fixed at U2830, but the first Unicode code is usually omitted\u003C\u002Fp>\u003Cp>During the code obfuscation process, we can deviate from the above syntax to increase the difficulty of code analysis\u003C\u002Fp>\u003Cp>For example, first encode the code in base64 (which consists of 64 characters), then randomly map it to the 256 zones of Braille Patterns\u003C\u002Fp>\u003Cp>In summary, we can derive the implementation principle: convert the characters to be encrypted into Unicode codes, and then convert the Unicode codes into actual symbols\u003C\u002Fp>\u003Cp>Therefore, decryption is also very simple: regardless of how complex the symbols are, first convert them into Unicode codes, then analyze them\u003C\u002Fp>\u003Cp>To improve efficiency, the following sections introduce the methods for programmatically implementing encoding and decoding\u003C\u002Fp>\u003Cp>For intuitive understanding, the program implementations all use Braille Grade 1 encoding, i.e., converting letter by letter, excluding abbreviations and other word-level transformations\u003C\u002Fp>\u003Ch2>0x03 Implementing Encoding via Program\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the implementation of encoding, simplicity and practicality are prioritized, so web-based encoding is chosen\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.byronknoll.com\u002Fbraille.html\u003C\u002Fp>\u003Cp>This website supports Braille Grade 1 encoding\u003C\u002Fp>\u003Cp>By viewing the source code, it can be found that http:\u002F\u002Fwww.byronknoll.com\u002Fbraille.html implements Braille Grade 1 encoding through JavaScript scripts\u003C\u002Fp>\u003Cp>Therefore, we only need to make simple modifications (fix some transcoding bugs, remove some features)\u003C\u002Fp>\u003Cp>To check if there are bugs in the transcoding process, we need to know the Unicode and HTML codes corresponding to each Braille character. Reference materials available:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.ziti163.com\u002Funi\u002F2800-28ff.shtml?id=83#\u003C\u002Fp>\u003Cp>The correspondence between Unicode codes and English characters can be referenced from:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.doc88.com\u002Fp-695153826363.html\u003C\u002Fp>\u003Cp>The original code supports uppercase and lowercase letters, numbers, and some special symbols, but there are some bugs in the handling of special symbols, such as incorrect conversion for + and !\u003C\u002Fp>\u003Cp>The modified code has been uploaded to GitHub and can be accessed directly for encoding at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002Ftool\u002FBrailleGenerator.html\u003C\u002Fp>\u003Cp>Supports the following characters: 1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ),!\u002F-.?;'$\u003C\u002Fp>\u003Cp>Test as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018765629_2_a0e6be5981.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My code only serves as a development template, so the conversion bugs for + and ! are not fixed, and + and = are not supported\u003C\u002Fp>\u003Ch2>0x04 Decoding via Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To combine with exploitation methods (e.g., in-memory loading of PE files), C# is used here for implementation\u003C\u002Fp>\u003Cp>For details on in-memory loading of PE files, refer to the previous article 'In-Memory Loading of PE Files via .NET'\u003C\u002Fp>\u003Cp>The program implementation process is as follows:\u003C\u002Fp>\u003Cp>1. Store the Braille characters obtained from BrailleGenerator.html in an array\u003C\u002Fp>\u003Cp>2. Convert Braille characters into Unicode characters, noting that Arabic numerals and uppercase letters occupy two Unicode characters\u003C\u002Fp>\u003Cp>3. Convert Unicode characters into actual characters through corresponding mappings\u003C\u002Fp>\u003Cp>The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Supports the following characters: 1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ),!\u002F-.?;'$\u003C\u002Fp>\u003Cp>Supports .NET 3.5 and newer versions\u003C\u002Fp>\u003Cp>The compilation command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe BrailleToASCII.cs\u003Cbr>or\u003Cbr>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe BrailleToASCII.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Approach for Encoding and Decoding Using Other Unicode Character Tables\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Encoding\u003C\u002Fh3>\u003Cp>Convert the code into Unicode, generate new Unicode codes through custom mapping relationships, and finally convert them into corresponding symbols\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Decoding\u003C\u002Fh3>\u003Cp>During exploitation, decrypt according to the encrypted mapping relationships\u003C\u002Fp>\u003Cp>If analyzing samples with obfuscated code, set breakpoints before the code loading process to obtain the decoded content\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses Braille Patterns as an example to introduce the basic method of obfuscating strings using Unicode encoding. It demonstrates encoding and decoding of Braille Patterns through programs and briefly discusses the approach for encoding and decoding using other Unicode character tables.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, critical code (such as shellcode) is often obfuscated to evade static detection and analysis.\u003C\u002Fp>\u003Cp>I recently encountered an interesting sample that uses Braille Patterns to obfuscate strings, posing significant challenges for static analysis.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018744999_0_216e3b210f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018750664_1_9787367b48-1.png\">\u003C\u002Fp>\u003Cp>Sample address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Ffile\u002F06f90a471f65de9f9805a9e907d365a04f4ebed1bf28b458397ad19afdb9ac00\u002Fdetection\u003C\u002Fp>\u003Cp>This article will introduce this method of obfuscating strings using Unicode encoding. It will cover implementing encoding and decoding for Braille Patterns through programs and share ideas for using other Unicode character tables for encoding and decoding.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation principles of the sample characters\u003C\u002Fli>\u003Cli>Encoding via program\u003C\u002Fli>\u003Cli>Decoding via program\u003C\u002Fli>\u003Cli>Approach to encoding and decoding using other Unicode character tables\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation principle of sample characters\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Basic Knowledge 1: Unicode\u003C\u002Fh3>\u003Cp>Unicode is an encoding scheme developed to overcome the limitations of traditional character encoding methods. It assigns a uniform and unique binary code to each character in every language, meeting the requirements for cross-language and cross-platform text conversion and processing.\u003C\u002Fp>\u003Cp>Simple understanding: Every character we see on a computer corresponds to a unique Unicode code.\u003C\u002Fp>\u003Cp>Applying this to the sample mentioned above, although Braille Patterns are used to create difficulty for manual analysis, converting each character into its Unicode code can overcome this problem.\u003C\u002Fp>\u003Ch3>Basic Knowledge 2: Braille Patterns\u003C\u002Fh3>\u003Cp>These are specialized text symbols designed for blind people to read by touch and write.\u003C\u002Fp>\u003Cp>Braille consists of 64 distinct patterns, meaning each character has 64 possible styles.\u003C\u002Fp>\u003Cp>Braille Patterns occupy 256 positions in the Unicode table, meaning there are 256 Unicode codes corresponding to Braille Patterns.\u003C\u002Fp>\u003Cp>To support more characters, the following method is used in the correspondence:\u003C\u002Fp>\u003Cul>\u003Cli>Lowercase English letters correspond to single Unicode codes\u003C\u002Fli>\u003Cli>Arabic numerals correspond to two Unicode codes, with the first Unicode code fixed at U283C\u003C\u002Fli>\u003Cli>Uppercase English letters correspond to two Unicode codes, with the first Unicode code fixed at U2820\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Lowercase English letters also correspond to two Unicode codes, with the first Unicode code fixed at U2830, but the first Unicode code is usually omitted\u003C\u002Fp>\u003Cp>During the code obfuscation process, we can deviate from the above syntax to increase the difficulty of code analysis\u003C\u002Fp>\u003Cp>For example, first encode the code in base64 (which consists of 64 characters), then randomly map it to the 256 zones of Braille Patterns\u003C\u002Fp>\u003Cp>In summary, we can derive the implementation principle: convert the characters to be encrypted into Unicode codes, and then convert the Unicode codes into actual symbols\u003C\u002Fp>\u003Cp>Therefore, decryption is also very simple: regardless of how complex the symbols are, first convert them into Unicode codes, then analyze them\u003C\u002Fp>\u003Cp>To improve efficiency, the following sections introduce the methods for programmatically implementing encoding and decoding\u003C\u002Fp>\u003Cp>For intuitive understanding, the program implementations all use Braille Grade 1 encoding, i.e., converting letter by letter, excluding abbreviations and other word-level transformations\u003C\u002Fp>\u003Ch2>0x03 Implementing Encoding via Program\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For the implementation of encoding, simplicity and practicality are prioritized, so web-based encoding is chosen\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.byronknoll.com\u002Fbraille.html\u003C\u002Fp>\u003Cp>This website supports Braille Grade 1 encoding\u003C\u002Fp>\u003Cp>By viewing the source code, it can be found that http:\u002F\u002Fwww.byronknoll.com\u002Fbraille.html implements Braille Grade 1 encoding through JavaScript scripts\u003C\u002Fp>\u003Cp>Therefore, we only need to make simple modifications (fix some transcoding bugs, remove some features)\u003C\u002Fp>\u003Cp>To check if there are bugs in the transcoding process, we need to know the Unicode and HTML codes corresponding to each Braille character. Reference materials available:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.ziti163.com\u002Funi\u002F2800-28ff.shtml?id=83#\u003C\u002Fp>\u003Cp>The correspondence between Unicode codes and English characters can be referenced from:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.doc88.com\u002Fp-695153826363.html\u003C\u002Fp>\u003Cp>The original code supports uppercase and lowercase letters, numbers, and some special symbols, but there are some bugs in the handling of special symbols, such as incorrect conversion for + and !\u003C\u002Fp>\u003Cp>The modified code has been uploaded to GitHub and can be accessed directly for encoding at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fan-open-source-project\u002Ftool\u002FBrailleGenerator.html\u003C\u002Fp>\u003Cp>Supports the following characters: 1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ),!\u002F-.?;'$\u003C\u002Fp>\u003Cp>Test as shown in the image below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018765629_2_a0e6be5981-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>My code only serves as a development template, so the conversion bugs for + and ! are not fixed, and + and = are not supported\u003C\u002Fp>\u003Ch2>0x04 Decoding via Program Implementation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To combine with exploitation methods (e.g., in-memory loading of PE files), C# is used here for implementation\u003C\u002Fp>\u003Cp>For details on in-memory loading of PE files, refer to the previous article 'In-Memory Loading of PE Files via .NET'\u003C\u002Fp>\u003Cp>The program implementation process is as follows:\u003C\u002Fp>\u003Cp>1. Store the Braille characters obtained from BrailleGenerator.html in an array\u003C\u002Fp>\u003Cp>2. Convert Braille characters into Unicode characters, noting that Arabic numerals and uppercase letters occupy two Unicode characters\u003C\u002Fp>\u003Cp>3. Convert Unicode characters into actual characters through corresponding mappings\u003C\u002Fp>\u003Cp>The code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Supports the following characters: 1234567890abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ),!\u002F-.?;'$\u003C\u002Fp>\u003Cp>Supports .NET 3.5 and newer versions\u003C\u002Fp>\u003Cp>The compilation command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework\\v3.5\\csc.exe BrailleToASCII.cs\u003Cbr>or\u003Cbr>C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe BrailleToASCII.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Approach for Encoding and Decoding Using Other Unicode Character Tables\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Encoding\u003C\u002Fh3>\u003Cp>Convert the code into Unicode, generate new Unicode codes through custom mapping relationships, and finally convert them into corresponding symbols\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Decoding\u003C\u002Fh3>\u003Cp>During exploitation, decrypt according to the encrypted mapping relationships\u003C\u002Fp>\u003Cp>If analyzing samples with obfuscated code, set breakpoints before the code loading process to obtain the decoded content\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses Braille Patterns as an example to introduce the basic method of obfuscating strings using Unicode encoding. It demonstrates encoding and decoding of Braille Patterns through programs and briefly discusses the approach for encoding and decoding using other Unicode character tables.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1512,"Onedaysec",5,"published","2026-02-02T08:08:32.700Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Unicode Obfuscation: Braille Patterns for Penetration Testing","penetration testing, obfuscation, Unicode encoding, Braille Patterns, static analysis evasion, shellcode obfuscation, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],214,213,211,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.709Z","2026-07-23T16:01:12.103Z","draft","2026-07-23T16:04:34.854Z"]