# Analysing Malicious Windows Programs ## The Windows API ##### Types and Hungarian Notation `DWORD` - 32 bit unsigned integer `WORD` - 16 bit unsigned integer Hungarian notation is where variables are prefixed with their data type e.g. `dwSize` has prefix `dw` for `DWORD` indicating it is a 32 bit unsigned int | Type and Prefix | Description | | ------------------- | ------------------------------------------------------------ | | `WORD` (`w`) | A 16 bit unsigned vvalue | | `DWORD` (`dw`) | A double word, 32-bit unsigned value | | Handles (`H`) | A reference to an object. The information stored in the handle is no documented, and the handle should be manipulated only by the Windows API | | Long Pointer (`LP`) | A pointer to another type e.g. `LPByte` is a pointer to a byte. Strings are usually prefixed with `LP` because they are actually pointers. | | Callback | Represents a function that will be called by the Windows API | ##### Handles *Handles* are items that have been opened or created in the OS, such as a window, process, module, menu, file etc. - Handles are like pointers in that they refer to an object or memory location - Unlike pointers handles cannot be used in arithmetic operations - The only use case is storing it and use it later in a function call ##### File System Functions Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system: - `CreateFile` - used to create and open files. It can open existing files, pipes, streams and I/O devices. - `ReadFile` and `WriteFile` - used for reading and writing to the contents of files. Both operate on files as a stream. - `CreateFileMapping` and `MapViewOfFile` - *File mappings* are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily. - `CreateFileMapping` loads a file from disk into memory - `MapViewOfFile` returns a pointer to the base address of the mapping, this can be used to access the file in memory ##### Special Files Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like `C:\docs`) ###### Shared Files Sharted files are special files with names that start with `\\serverName\share` or `\\?\serverName\share` - They access directories or files in a shared folder stored on a network. - `\\?\` prefix tells the OS to disable all string parsing and allows access to longer filenames ###### Files Accessible via Namespaces *Namespaces* can be thought of as a fixed number of folders, each storing different types of objects - The lowest level namespace is `NT` with the prefix `\.` - The `NT` namespace has access to all devices, and all other namespaces exist within the `NT` namespace The `Win32` device namespace (prefix `\\.\`) is often used to access physical devices directly and read/write to them like a file. - `\\.\PhysicalDisk1` to directly access the disk while ignoring its file system - By doing this malware can read and write data to an unallocated sector in the drive without creating a file - This is very good for avoiding detection ###### Alternate Data Streams ADS allows additional data to be addwed to an existing file within `NTFS` - The extra data doesn’t show up in a directory listing nor when displaying the contents of the file - It’s only visible when accessing the stream - ADS data is named `normalFile.txt:Stream:$DATA` ## The Windows Registry The *Windows registry* is used to store OS and program configuration information, such as settings and options. In early versions of windows the registry was just a hierarchy of `.ini` files to improve performance. Malware often uses the registry for *persistence* or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots. - **Root key** - The registry is divided into five top-level sections called *root keys* (sometimes called `HKEY`) - **Subkey** - Akin to a subfolder within a folder - **Key** - A key is a folder in the registry that can contain additional folders or values - The root key and subkey are both keys - **Value entry** - A *value entry* is an ordered pair with a name and value - **Value or data** - The data stored in a registry entry #### Registry Root Keys - `HKEY_LOCAL_MACHINE` (`HKLM`) - Stores settings that are global to the local machine - Contains ` HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run` - This is the key that stores a list of executables that are run at start up - `HKEY_CURRENT_USER` (`HKCU`) - Stores settings specific to the current user - This is a virtual key, stored in `HKEY_USERS\SID` - Where `SID` is the security identifier of the user currently logged in - `HKEY_CLASSES ROOT` - Stores information defining types - `HKEY_CURRENT_CONFIG` - Stores settings about the current hardware configuration, specifically differences between the current and standard configuration - `HKEY_USERS` - Defines settings for the default user, new user and current user ##### Common Registry Functions - `RegOpenKeyEx` - Opens a registry for editing and querying - `RegSetValueEx` - Adds a new value to the registry and sets its data - `RegGetValue` - Returns the data for a value entry in the registry You can use RegEdit to view and edit the registry. ### Networking APIs ![1646936140.png](img/1646936140.png) ## Following Malware Execution #### DLLs To store malicious code: - Malware often uses a `dll` to load itself into another process - This is because one process can only contain one `.exe` By using Windows `dll`s: - Windows dlls contain the functionality to interact with the OS - By looking at what dlls are used can help find the functionality of the malware By using third-party `dll`s - This can provide further insight to what the malware does - e.g. if it uses a mozilla `dll` instead of the standard windows api, it might be usiing functions not found in the windows api such as encryption `DLL`s are similar to `EXE`s, there’s a flag in the PE to indicate the file is a dll. #### Processes - Malware can execute outside the current program by creating a new process or modifying an existing one. - A process is a program being executed by Windows - Each process manages its own resources such as open handles and memory - A process contains one or more threads that are executed by the CPU. - `CreateProcess` can be used to create a new process #### Threads Processes are the container for execution, but *threads* are what the windows OS executes. - Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads - A process contains one or more threads, which execute part of the code within a process. - Threads within a process all share a memory space but have seperate registers and stack `CreateThread` can be used to create new threads 1. Malware can use `CreateThread` to load a new malicious library into a process with `CreateThread` called and the address of `LoadLibrary` as the start address 2. Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket. #### Services Another way for malware to execute additional code is by installing it as a *service*. - Windows allows tasks to run without their own processes or threads by using services that run as background applications - Code is scheduled and run by the Windows service manager without user input. - Services are normally run as `SYSTEM` or another privileged account - Key service functions: - `OpenSCManager` Returns a handle to the service control manager - `CreateService` - Adds a new service to the service control manager - Allows caller to specify whether the service will start automatically at boot time, or started manually - `StartService` Starts the service, only used if service needs to be started manually