Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -3,46 +3,46 @@
|
||||
### Basic Static Analysis
|
||||
|
||||
- Examining the executable file without viewing the actual instructions
|
||||
- This can confirm whether a file is malicious
|
||||
- Provide information about its functionality
|
||||
- Provide information that will allow us to produce network signatures
|
||||
- This can confirm whether a file is malicious
|
||||
- Provide information about its functionality
|
||||
- Provide information that will allow us to produce network signatures
|
||||
- Basic static analysis is straightforward and quick
|
||||
- However is largely ineffective against sophisticated malware.
|
||||
- However, it is largely ineffective against sophisticated malware.
|
||||
|
||||
##### Techniques
|
||||
|
||||
- Using **antivirus tools** to confirm maliciousness
|
||||
- virus total is an online tool to scan files for known malware
|
||||
- VirusTotal is an online tool to scan files for known malware
|
||||
- Using **hashes** to identify malware
|
||||
- When the file is run through a hashing algorithm (often `md5` or `SHA-1`) it uniquely identifies it.
|
||||
- This is useful to see if other malware analysts have seen this malware
|
||||
- When the file is run through a hashing algorithm (often `md5` or `SHA-1`) it uniquely identifies it.
|
||||
- This is useful to see if other malware analysts have seen this malware
|
||||
- Gleaning information from a **file’s strings**, functions and headers
|
||||
- Note: microsoft uses the term wide character to describe its implementation of Uni-code strings.
|
||||
- Strings can return
|
||||
- IP addresses to where the malware is sending/receiving
|
||||
- Windows system calls like `GetLayout` & `SetLayout` which are used in windows graphics library
|
||||
- Windows libraries such as `GDI32.DLL` which is a graphics library.
|
||||
- Therefore we can infer this malware opens a GUI display
|
||||
- Note: strings will show the executable’s manifest at the end, a brief `xml` file.
|
||||
- Note: Microsoft uses the term wide character to describe its implementation of Unicode strings.
|
||||
- Strings can return
|
||||
- IP addresses to where the malware is sending/receiving
|
||||
- Windows system calls like `GetLayout` & `SetLayout` which are used in the Windows graphics library
|
||||
- Windows libraries such as `GDI32.DLL` which is a graphics library.
|
||||
- Therefore we can infer this malware opens a GUI display
|
||||
- Note: strings will show the executable’s manifest at the end, a brief `xml` file.
|
||||
|
||||
### Basic Dynamic Analysis
|
||||
|
||||
- Running the malware and observing its behaviour on the system in order to:
|
||||
- remove the infection
|
||||
- produce effective signatures
|
||||
- Is important to note that a safe environment should be set up, so that the malware can be run without risk of damage to your system or network
|
||||
- remove the infection
|
||||
- produce effective signatures
|
||||
- It is important to note that a safe environment should be set up, so that the malware can be run without risk of damage to your system or network
|
||||
- Like basic static analysis, this can be useful but can miss important functionality
|
||||
|
||||
### Advanced Static Analysis
|
||||
|
||||
- Reverse-engineering the malware’s internals by loading the executable into a disassembler
|
||||
- This involves looking at the instructions to discover what the malware does
|
||||
- This requires an in-depth knowledge of disassembly, code constructs and windows operating system constructs
|
||||
- This involves looking at the instructions to discover what the malware does
|
||||
- This requires an in-depth knowledge of disassembly, code constructs and Windows operating system constructs
|
||||
|
||||
#### Problems with Static Analysis
|
||||
|
||||
- Only shows us what is in the program
|
||||
- Not how it is used (if it used at all)
|
||||
- Not how it is used (if it is used at all)
|
||||
- Might see potential filename - but is that file created or deleted
|
||||
- Does it get used every time the program is run or under certain circumstances
|
||||
- Unsure of sequence of events
|
||||
@@ -89,7 +89,7 @@ One of the most useful pieces of information we can gather about a program is th
|
||||
|
||||
When a library is statically linked, all code from that library is copied into the executable which makes the executable grow in size.
|
||||
|
||||
- It is difficult to differentiate between the programs code and the imported code as nothing in the PE header suggests the file contains linked code
|
||||
- It is difficult to differentiate between the program’s code and the imported code as nothing in the PE header suggests the file contains linked code
|
||||
- This is the most uncommon method of linking
|
||||
|
||||
##### Run-time Linking
|
||||
@@ -97,7 +97,7 @@ When a library is statically linked, all code from that library is copied into t
|
||||
- Run-time linking is commonly used by malware, especially when packed or obfuscated
|
||||
- Executable files connect to libraries only when that function is needed, **not at program start**
|
||||
- `GetProcAddress` and `LoadLibrary` allow the program to access any function in any library on the system.
|
||||
- This means when functions are used, we cannot tell statically which functions are linked.
|
||||
- This means when functions are used, we cannot tell statically which functions are linked.
|
||||
|
||||
##### Dynamic Linking
|
||||
|
||||
@@ -108,24 +108,24 @@ When libraries are dynamically linked, the host OS searches for necessary librar
|
||||
#### Commonly linked DLLs
|
||||
|
||||
- `Kernel32.dll`
|
||||
- Very common library contains core functionality such as access & manipulation of memory, files and hardware.
|
||||
- Very common library contains core functionality such as access & manipulation of memory, files and hardware.
|
||||
- `User32.dll`
|
||||
- This `DLL` contains all the user-interface components such as buttons, scrolling etc
|
||||
- This `DLL` contains all the user-interface components such as buttons, scrolling etc
|
||||
|
||||
#### Common imported functions
|
||||
|
||||
The PE file header also includes information about specific functions used by an executable. The names alone will give clues however microsoft documents everything on MSDN
|
||||
The PE file header also includes information about specific functions used by an executable. The names alone will give clues; however, Microsoft documents everything on MSDN
|
||||
|
||||
- `FindFirstFileW`, `FindNextFileW`, `FindClose`
|
||||
- These all involve searching the users system for files
|
||||
- `FindFirstFileW` will include a string for regex, so we can see if its searching for all files `./*` or a specific `myFile.exe`
|
||||
- These all involve searching the user’s system for files
|
||||
- `FindFirstFileW` will include a string for regex, so we can see if it’s searching for all files `./*` or a specific `myFile.exe`
|
||||
- `ReadFile`, `WriteFile`
|
||||
- `SetWindowsHookExW`
|
||||
- Often used to implement keylogs
|
||||
- Often used to implement keylogs
|
||||
- `CreateWindowExW`, `DefWindowProcW`, `getWindowsTextW`, `setWindowsTextW` etc
|
||||
- This relates to setting up a GUI
|
||||
- This relates to setting up a GUI
|
||||
- `RegisterHotkey`
|
||||
- Find what this keypress is, to see what it does
|
||||
- Find what this keypress is, to see what it does
|
||||
|
||||
#### PE Header Summary
|
||||
|
||||
@@ -137,4 +137,3 @@ The PE file header also includes information about specific functions used by an
|
||||
| Sections | Names of sections in the file and their sizes on disk and in memory |
|
||||
| Subsystem | Indicates whether the program is a command-line or GUI application |
|
||||
| Resources | Strings, icons, menus |
|
||||
|
||||
Reference in new issue
Block a user