Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,163 @@
|
||||
# Analysing Malicious Windows Programs
|
||||
|
||||
## The Windows API
|
||||
|
||||
##### Types and Hungarian Notation
|
||||
|
||||
`DWORD` - 32 bit unsigned integer
|
||||
|
||||
`WORD` - 16 bit unsigned integer
|
||||
|
||||
Hungarian notation is where variables are prefixed with their data type e.g. `dwSize` has prefix `dw` for `DWORD` indicating it is a 32 bit unsigned int
|
||||
|
||||
| Type and Prefix | Description |
|
||||
| ------------------- | ------------------------------------------------------------ |
|
||||
| `WORD` (`w`) | A 16 bit unsigned vvalue |
|
||||
| `DWORD` (`dw`) | A double word, 32-bit unsigned value |
|
||||
| Handles (`H`) | A reference to an object. The information stored in the handle is no documented, and the handle should be manipulated only by the Windows API |
|
||||
| Long Pointer (`LP`) | A pointer to another type e.g. `LPByte` is a pointer to a byte. Strings are usually prefixed with `LP` because they are actually pointers. |
|
||||
| Callback | Represents a function that will be called by the Windows API |
|
||||
|
||||
##### Handles
|
||||
|
||||
*Handles* are items that have been opened or created in the OS, such as a window, process, module, menu, file etc.
|
||||
|
||||
- Handles are like pointers in that they refer to an object or memory location
|
||||
- Unlike pointers handles cannot be used in arithmetic operations
|
||||
- The only use case is storing it and use it later in a function call
|
||||
|
||||
##### File System Functions
|
||||
|
||||
Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system:
|
||||
|
||||
- `CreateFile` - used to create and open files. It can open existing files, pipes, streams and I/O devices.
|
||||
- `ReadFile` and `WriteFile` - used for reading and writing to the contents of files. Both operate on files as a stream.
|
||||
- `CreateFileMapping` and `MapViewOfFile` - *File mappings* are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily.
|
||||
- `CreateFileMapping` loads a file from disk into memory
|
||||
- `MapViewOfFile` returns a pointer to the base address of the mapping, this can be used to access the file in memory
|
||||
|
||||
##### Special Files
|
||||
|
||||
Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like `C:\docs`)
|
||||
|
||||
###### Shared Files
|
||||
|
||||
Sharted files are special files with names that start with `\\serverName\share` or `\\?\serverName\share`
|
||||
|
||||
- They access directories or files in a shared folder stored on a network.
|
||||
- `\\?\` prefix tells the OS to disable all string parsing and allows access to longer filenames
|
||||
|
||||
###### Files Accessible via Namespaces
|
||||
|
||||
*Namespaces* can be thought of as a fixed number of folders, each storing different types of objects
|
||||
|
||||
- The lowest level namespace is `NT` with the prefix `\.`
|
||||
- The `NT` namespace has access to all devices, and all other namespaces exist within the `NT` namespace
|
||||
|
||||
The `Win32` device namespace (prefix `\\.\`) is often used to access physical devices directly and read/write to them like a file.
|
||||
|
||||
- `\\.\PhysicalDisk1` to directly access the disk while ignoring its file system
|
||||
- By doing this malware can read and write data to an unallocated sector in the drive without creating a file
|
||||
- This is very good for avoiding detection
|
||||
|
||||
###### Alternate Data Streams
|
||||
|
||||
ADS allows additional data to be addwed to an existing file within `NTFS`
|
||||
|
||||
- The extra data doesn’t show up in a directory listing nor when displaying the contents of the file
|
||||
- It’s only visible when accessing the stream
|
||||
- ADS data is named `normalFile.txt:Stream:$DATA`
|
||||
|
||||
## The Windows Registry
|
||||
|
||||
The *Windows registry* is used to store OS and program configuration information, such as settings and options.
|
||||
|
||||
In early versions of windows the registry was just a hierarchy of `.ini` files to improve performance.
|
||||
|
||||
Malware often uses the registry for *persistence* or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots.
|
||||
|
||||
- **Root key** - The registry is divided into five top-level sections called *root keys* (sometimes called `HKEY`)
|
||||
- **Subkey** - Akin to a subfolder within a folder
|
||||
- **Key** - A key is a folder in the registry that can contain additional folders or values
|
||||
- The root key and subkey are both keys
|
||||
- **Value entry** - A *value entry* is an ordered pair with a name and value
|
||||
- **Value or data** - The data stored in a registry entry
|
||||
|
||||
#### Registry Root Keys
|
||||
|
||||
- `HKEY_LOCAL_MACHINE` (`HKLM`) - Stores settings that are global to the local machine
|
||||
- Contains ` HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
|
||||
- This is the key that stores a list of executables that are run at start up
|
||||
- `HKEY_CURRENT_USER` (`HKCU`) - Stores settings specific to the current user
|
||||
- This is a virtual key, stored in `HKEY_USERS\SID`
|
||||
- Where `SID` is the security identifier of the user currently logged in
|
||||
- `HKEY_CLASSES ROOT` - Stores information defining types
|
||||
- `HKEY_CURRENT_CONFIG` - Stores settings about the current hardware configuration, specifically differences between the current and standard configuration
|
||||
- `HKEY_USERS` - Defines settings for the default user, new user and current user
|
||||
|
||||
##### Common Registry Functions
|
||||
|
||||
- `RegOpenKeyEx` - Opens a registry for editing and querying
|
||||
- `RegSetValueEx` - Adds a new value to the registry and sets its data
|
||||
- `RegGetValue` - Returns the data for a value entry in the registry
|
||||
|
||||
You can use RegEdit to view and edit the registry.
|
||||
|
||||
### Networking APIs
|
||||
|
||||

|
||||
|
||||
## Following Malware Execution
|
||||
|
||||
#### DLLs
|
||||
|
||||
To store malicious code:
|
||||
|
||||
- Malware often uses a `dll` to load itself into another process
|
||||
- This is because one process can only contain one `.exe`
|
||||
|
||||
By using Windows `dll`s:
|
||||
|
||||
- Windows dlls contain the functionality to interact with the OS
|
||||
- By looking at what dlls are used can help find the functionality of the malware
|
||||
|
||||
By using third-party `dll`s
|
||||
|
||||
- This can provide further insight to what the malware does
|
||||
- e.g. if it uses a mozilla `dll` instead of the standard windows api, it might be usiing functions not found in the windows api such as encryption
|
||||
|
||||
`DLL`s are similar to `EXE`s, there’s a flag in the PE to indicate the file is a dll.
|
||||
|
||||
#### Processes
|
||||
|
||||
- Malware can execute outside the current program by creating a new process or modifying an existing one.
|
||||
- A process is a program being executed by Windows
|
||||
- Each process manages its own resources such as open handles and memory
|
||||
- A process contains one or more threads that are executed by the CPU.
|
||||
- `CreateProcess` can be used to create a new process
|
||||
|
||||
#### Threads
|
||||
|
||||
Processes are the container for execution, but *threads* are what the windows OS executes.
|
||||
|
||||
- Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads
|
||||
- A process contains one or more threads, which execute part of the code within a process.
|
||||
- Threads within a process all share a memory space but have seperate registers and stack
|
||||
|
||||
`CreateThread` can be used to create new threads
|
||||
|
||||
1. Malware can use `CreateThread` to load a new malicious library into a process with `CreateThread` called and the address of `LoadLibrary` as the start address
|
||||
2. Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket.
|
||||
|
||||
#### Services
|
||||
|
||||
Another way for malware to execute additional code is by installing it as a *service*.
|
||||
|
||||
- Windows allows tasks to run without their own processes or threads by using services that run as background applications
|
||||
- Code is scheduled and run by the Windows service manager without user input.
|
||||
- Services are normally run as `SYSTEM` or another privileged account
|
||||
- Key service functions:
|
||||
- `OpenSCManager` Returns a handle to the service control manager
|
||||
- `CreateService` - Adds a new service to the service control manager
|
||||
- Allows caller to specify whether the service will start automatically at boot time, or started manually
|
||||
- `StartService` Starts the service, only used if service needs to be started manually
|
||||
Reference in new issue
Block a user