Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,64 @@
|
||||
# Dynamic Analysis
|
||||
|
||||
Programs = data structures + algorithms
|
||||
|
||||
- All programs (including malware) are a series of instructions
|
||||
- That get executed by the CPU
|
||||
- By observing these instructions as they run, we can see what the program actually does
|
||||
|
||||
##### Internal Actions
|
||||
|
||||
- Some of the instructions will cause things to happen within the program
|
||||
- Only affecting the data within the program
|
||||
- We can analyse this but it requires us to get inside the program and watch what it does internally
|
||||
- Using tools like a *debugger*
|
||||
- Requires understanding of machine code
|
||||
|
||||
##### External Actions
|
||||
|
||||
- Programs also have effects outside the program
|
||||
- Can monitor the external actions and get an idea about the programs activity
|
||||
- Not just what the program does but also the order the program performs those actions
|
||||
|
||||
##### Running the Malware
|
||||
|
||||
Note:
|
||||
|
||||
- It is important that dynamic analysis is done after the program has been statically analysed
|
||||
- This is because the malware can put your system and network at risk
|
||||
- Can be tricky to make the malware run
|
||||
- If its distributed as a `.exe`, then we can just run it
|
||||
- But might do different things based on command line options
|
||||
- If its distributed as `.DLL`, then its more complicated
|
||||
- Can use `rundll32.exe` to start it and specify the export to call
|
||||
- As a last resort you can force the `.dll` to behave as a `.exe` by editing the PE header
|
||||
|
||||
#### Monitoring with Process Monitor - ProcMon
|
||||
|
||||
Process Monitor or procmon is an advanced monitoring tool for Windows that provides a way to monitor certain registry, file system, process and thread activity.
|
||||
|
||||
- Procmon monitors all system calls
|
||||
- Because there are so many system calls (around 50,000 per minute) it is import to filter by type
|
||||
- Filter by:
|
||||
- **Registry** - Tells us how malware installs itself into the registry
|
||||
- **File System** - Shows us all the files that the malware creates or config files it uses
|
||||
- **Process Activity** - Tells us if the malware spawns any additional processes
|
||||
- **Network** - Shows us if the malware is listening on any specific ports
|
||||
|
||||
#### Comparing Registry Snapshots - RegShot
|
||||
|
||||
An open-source registry comparison tool that allows you to take and compare two registry snapshots.
|
||||
|
||||
- We can look for added values
|
||||
- A malware has added a new registry key
|
||||
- Or modified keys
|
||||
- A malware has modified a registry perhaps inserting itself into non-malicious software
|
||||
|
||||
### General Steps
|
||||
|
||||
1. Run procmon
|
||||
2. Run process explorer
|
||||
3. Get an initial snapshot with RegShot
|
||||
4. Run the malware
|
||||
5. Take another snapshot and compare, also analysing procmon and process explorer.
|
||||
|
||||
Reference in new issue
Block a user