This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+30 -31
View File
@@ -3,46 +3,46 @@
### Basic Static Analysis
- Examining the executable file without viewing the actual instructions
- This can confirm whether a file is malicious
- Provide information about its functionality
- Provide information that will allow us to produce network signatures
- This can confirm whether a file is malicious
- Provide information about its functionality
- Provide information that will allow us to produce network signatures
- Basic static analysis is straightforward and quick
- However is largely ineffective against sophisticated malware.
- However, it is largely ineffective against sophisticated malware.
##### Techniques
- Using **antivirus tools** to confirm maliciousness
- virus total is an online tool to scan files for known malware
- VirusTotal is an online tool to scan files for known malware
- Using **hashes** to identify malware
- When the file is run through a hashing algorithm (often `md5` or `SHA-1`) it uniquely identifies it.
- This is useful to see if other malware analysts have seen this malware
- When the file is run through a hashing algorithm (often `md5` or `SHA-1`) it uniquely identifies it.
- This is useful to see if other malware analysts have seen this malware
- Gleaning information from a **file’s strings**, functions and headers
- Note: microsoft uses the term wide character to describe its implementation of Uni-code strings.
- Strings can return
- IP addresses to where the malware is sending/receiving
- Windows system calls like `GetLayout` & `SetLayout` which are used in windows graphics library
- Windows libraries such as `GDI32.DLL` which is a graphics library.
- Therefore we can infer this malware opens a GUI display
- Note: strings will show the executable’s manifest at the end, a brief `xml` file.
- Note: Microsoft uses the term wide character to describe its implementation of Unicode strings.
- Strings can return
- IP addresses to where the malware is sending/receiving
- Windows system calls like `GetLayout` & `SetLayout` which are used in the Windows graphics library
- Windows libraries such as `GDI32.DLL` which is a graphics library.
- Therefore we can infer this malware opens a GUI display
- Note: strings will show the executable’s manifest at the end, a brief `xml` file.
### Basic Dynamic Analysis
- Running the malware and observing its behaviour on the system in order to:
- remove the infection
- produce effective signatures
- Is important to note that a safe environment should be set up, so that the malware can be run without risk of damage to your system or network
- remove the infection
- produce effective signatures
- It is important to note that a safe environment should be set up, so that the malware can be run without risk of damage to your system or network
- Like basic static analysis, this can be useful but can miss important functionality
### Advanced Static Analysis
- Reverse-engineering the malware’s internals by loading the executable into a disassembler
- This involves looking at the instructions to discover what the malware does
- This requires an in-depth knowledge of disassembly, code constructs and windows operating system constructs
- This involves looking at the instructions to discover what the malware does
- This requires an in-depth knowledge of disassembly, code constructs and Windows operating system constructs
#### Problems with Static Analysis
- Only shows us what is in the program
- Not how it is used (if it used at all)
- Not how it is used (if it is used at all)
- Might see potential filename - but is that file created or deleted
- Does it get used every time the program is run or under certain circumstances
- Unsure of sequence of events
@@ -89,7 +89,7 @@ One of the most useful pieces of information we can gather about a program is th
When a library is statically linked, all code from that library is copied into the executable which makes the executable grow in size.
- It is difficult to differentiate between the programs code and the imported code as nothing in the PE header suggests the file contains linked code
- It is difficult to differentiate between the program’s code and the imported code as nothing in the PE header suggests the file contains linked code
- This is the most uncommon method of linking
##### Run-time Linking
@@ -97,7 +97,7 @@ When a library is statically linked, all code from that library is copied into t
- Run-time linking is commonly used by malware, especially when packed or obfuscated
- Executable files connect to libraries only when that function is needed, **not at program start**
- `GetProcAddress` and `LoadLibrary` allow the program to access any function in any library on the system.
- This means when functions are used, we cannot tell statically which functions are linked.
- This means when functions are used, we cannot tell statically which functions are linked.
##### Dynamic Linking
@@ -108,24 +108,24 @@ When libraries are dynamically linked, the host OS searches for necessary librar
#### Commonly linked DLLs
- `Kernel32.dll`
- Very common library contains core functionality such as access & manipulation of memory, files and hardware.
- Very common library contains core functionality such as access & manipulation of memory, files and hardware.
- `User32.dll`
- This `DLL` contains all the user-interface components such as buttons, scrolling etc
- This `DLL` contains all the user-interface components such as buttons, scrolling etc
#### Common imported functions
The PE file header also includes information about specific functions used by an executable. The names alone will give clues however microsoft documents everything on MSDN
The PE file header also includes information about specific functions used by an executable. The names alone will give clues; however, Microsoft documents everything on MSDN
- `FindFirstFileW`, `FindNextFileW`, `FindClose`
- These all involve searching the users system for files
- `FindFirstFileW` will include a string for regex, so we can see if its searching for all files `./*` or a specific `myFile.exe`
- These all involve searching the user’s system for files
- `FindFirstFileW` will include a string for regex, so we can see if it’s searching for all files `./*` or a specific `myFile.exe`
- `ReadFile`, `WriteFile`
- `SetWindowsHookExW`
- Often used to implement keylogs
- Often used to implement keylogs
- `CreateWindowExW`, `DefWindowProcW`, `getWindowsTextW`, `setWindowsTextW` etc
- This relates to setting up a GUI
- This relates to setting up a GUI
- `RegisterHotkey`
- Find what this keypress is, to see what it does
- Find what this keypress is, to see what it does
#### PE Header Summary
@@ -137,4 +137,3 @@ The PE file header also includes information about specific functions used by an
| Sections | Names of sections in the file and their sizes on disk and in memory |
| Subsystem | Indicates whether the program is a command-line or GUI application |
| Resources | Strings, icons, menus |