Add the rest of university notes

This commit is contained in:
John Gatward committed 2026-10-04 14:02:35 +01:00
1 parent c1b84c7f7d
commit d0f27f276b
366 files changed
+9844 -110

No files matched your search

@@ -0,0 +1,163 @@
# Analysing Malicious Windows Programs
## The Windows API
##### Types and Hungarian Notation
`DWORD` - 32 bit unsigned integer
`WORD` - 16 bit unsigned integer
Hungarian notation is where variables are prefixed with their data type e.g. `dwSize` has prefix `dw` for `DWORD` indicating it is a 32 bit unsigned int
| Type and Prefix | Description |
| ------------------- | ------------------------------------------------------------ |
| `WORD` (`w`) | A 16 bit unsigned vvalue |
| `DWORD` (`dw`) | A double word, 32-bit unsigned value |
| Handles (`H`) | A reference to an object. The information stored in the handle is no documented, and the handle should be manipulated only by the Windows API |
| Long Pointer (`LP`) | A pointer to another type e.g. `LPByte` is a pointer to a byte. Strings are usually prefixed with `LP` because they are actually pointers. |
| Callback | Represents a function that will be called by the Windows API |
##### Handles
*Handles* are items that have been opened or created in the OS, such as a window, process, module, menu, file etc.
- Handles are like pointers in that they refer to an object or memory location
- Unlike pointers handles cannot be used in arithmetic operations
- The only use case is storing it and use it later in a function call
##### File System Functions
Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system:
- `CreateFile` - used to create and open files. It can open existing files, pipes, streams and I/O devices.
- `ReadFile` and `WriteFile` - used for reading and writing to the contents of files. Both operate on files as a stream.
- `CreateFileMapping` and `MapViewOfFile` - *File mappings* are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily.
- `CreateFileMapping` loads a file from disk into memory
- `MapViewOfFile` returns a pointer to the base address of the mapping, this can be used to access the file in memory
##### Special Files
Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like `C:\docs`)
###### Shared Files
Sharted files are special files with names that start with `\\serverName\share` or `\\?\serverName\share`
- They access directories or files in a shared folder stored on a network.
- `\\?\` prefix tells the OS to disable all string parsing and allows access to longer filenames
###### Files Accessible via Namespaces
*Namespaces* can be thought of as a fixed number of folders, each storing different types of objects
- The lowest level namespace is `NT` with the prefix `\.`
- The `NT` namespace has access to all devices, and all other namespaces exist within the `NT` namespace
The `Win32` device namespace (prefix `\\.\`) is often used to access physical devices directly and read/write to them like a file.
- `\\.\PhysicalDisk1` to directly access the disk while ignoring its file system
- By doing this malware can read and write data to an unallocated sector in the drive without creating a file
- This is very good for avoiding detection
###### Alternate Data Streams
ADS allows additional data to be addwed to an existing file within `NTFS`
- The extra data doesn’t show up in a directory listing nor when displaying the contents of the file
- It’s only visible when accessing the stream
- ADS data is named `normalFile.txt:Stream:$DATA`
## The Windows Registry
The *Windows registry* is used to store OS and program configuration information, such as settings and options.
In early versions of windows the registry was just a hierarchy of `.ini` files to improve performance.
Malware often uses the registry for *persistence* or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots.
- **Root key** - The registry is divided into five top-level sections called *root keys* (sometimes called `HKEY`)
- **Subkey** - Akin to a subfolder within a folder
- **Key** - A key is a folder in the registry that can contain additional folders or values
- The root key and subkey are both keys
- **Value entry** - A *value entry* is an ordered pair with a name and value
- **Value or data** - The data stored in a registry entry
#### Registry Root Keys
- `HKEY_LOCAL_MACHINE` (`HKLM`) - Stores settings that are global to the local machine
- Contains ` HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
- This is the key that stores a list of executables that are run at start up
- `HKEY_CURRENT_USER` (`HKCU`) - Stores settings specific to the current user
- This is a virtual key, stored in `HKEY_USERS\SID`
- Where `SID` is the security identifier of the user currently logged in
- `HKEY_CLASSES ROOT` - Stores information defining types
- `HKEY_CURRENT_CONFIG` - Stores settings about the current hardware configuration, specifically differences between the current and standard configuration
- `HKEY_USERS` - Defines settings for the default user, new user and current user
##### Common Registry Functions
- `RegOpenKeyEx` - Opens a registry for editing and querying
- `RegSetValueEx` - Adds a new value to the registry and sets its data
- `RegGetValue` - Returns the data for a value entry in the registry
You can use RegEdit to view and edit the registry.
### Networking APIs
![1646936140.png](img/1646936140.png)
## Following Malware Execution
#### DLLs
To store malicious code:
- Malware often uses a `dll` to load itself into another process
- This is because one process can only contain one `.exe`
By using Windows `dll`s:
- Windows dlls contain the functionality to interact with the OS
- By looking at what dlls are used can help find the functionality of the malware
By using third-party `dll`s
- This can provide further insight to what the malware does
- e.g. if it uses a mozilla `dll` instead of the standard windows api, it might be usiing functions not found in the windows api such as encryption
`DLL`s are similar to `EXE`s, there’s a flag in the PE to indicate the file is a dll.
#### Processes
- Malware can execute outside the current program by creating a new process or modifying an existing one.
- A process is a program being executed by Windows
- Each process manages its own resources such as open handles and memory
- A process contains one or more threads that are executed by the CPU.
- `CreateProcess` can be used to create a new process
#### Threads
Processes are the container for execution, but *threads* are what the windows OS executes.
- Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads
- A process contains one or more threads, which execute part of the code within a process.
- Threads within a process all share a memory space but have seperate registers and stack
`CreateThread` can be used to create new threads
1. Malware can use `CreateThread` to load a new malicious library into a process with `CreateThread` called and the address of `LoadLibrary` as the start address
2. Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket.
#### Services
Another way for malware to execute additional code is by installing it as a *service*.
- Windows allows tasks to run without their own processes or threads by using services that run as background applications
- Code is scheduled and run by the Windows service manager without user input.
- Services are normally run as `SYSTEM` or another privileged account
- Key service functions:
- `OpenSCManager` Returns a handle to the service control manager
- `CreateService` - Adds a new service to the service control manager
- Allows caller to specify whether the service will start automatically at boot time, or started manually
- `StartService` Starts the service, only used if service needs to be started manually