Files
notes/docs/lectures/malware/05_windows_analysis.md
T
2026-10-04 15:24:17 +01:00

8.1 KiB
Raw Blame History

Analysing Malicious Windows Programs

The Windows API

Types and Hungarian Notation

DWORD - 32-bit unsigned integer

WORD - 16-bit unsigned integer

Hungarian notation is where variables are prefixed with their data type e.g. dwSize has prefix dw for DWORD indicating it is a 32-bit unsigned int

Type and Prefix Description
WORD (w) A 16-bit unsigned value
DWORD (dw) A double word, 32-bit unsigned value
Handles (H) A reference to an object. The information stored in the handle is not documented, and the handle should be manipulated only by the Windows API
Long Pointer (LP) A pointer to another type e.g. LPByte is a pointer to a byte. Strings are usually prefixed with LP because they are actually pointers.
Callback Represents a function that will be called by the Windows API
Handles

Handles are items that have been opened or created in the OS, such as a window, process, module, menu, file etc.

  • Handles are like pointers in that they refer to an object or memory location
    • Unlike pointers handles cannot be used in arithmetic operations
  • The only use case is storing it and using it later in a function call
File System Functions

Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system:

  • CreateFile - used to create and open files. It can open existing files, pipes, streams and I/O devices.
  • ReadFile and WriteFile - used for reading and writing to the contents of files. Both operate on files as a stream.
  • CreateFileMapping and MapViewOfFile - File mappings are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily.
    • CreateFileMapping loads a file from disk into memory
    • MapViewOfFile returns a pointer to the base address of the mapping, this can be used to access the file in memory
Special Files

Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like C:\docs)

Shared Files

Shared files are special files with names that start with \\serverName\share or \\?\serverName\share

  • They access directories or files in a shared folder stored on a network.
    • \\?\ prefix tells the OS to disable all string parsing and allows access to longer filenames
Files Accessible via Namespaces

Namespaces can be thought of as a fixed number of folders, each storing different types of objects

  • The lowest level namespace is NT with the prefix \.
  • The NT namespace has access to all devices, and all other namespaces exist within the NT namespace

The Win32 device namespace (prefix \\.\) is often used to access physical devices directly and read/write to them like a file.

  • \\.\PhysicalDisk1 to directly access the disk while ignoring its file system
  • By doing this malware can read and write data to an unallocated sector in the drive without creating a file
    • This is very good for avoiding detection
Alternate Data Streams

ADS allows additional data to be added to an existing file within NTFS

  • The extra data doesn’t show up in a directory listing nor when displaying the contents of the file
    • It’s only visible when accessing the stream
  • ADS data is named normalFile.txt:Stream:$DATA

The Windows Registry

The Windows registry is used to store OS and program configuration information, such as settings and options.

In early versions of Windows the registry was just a hierarchy of .ini files to improve performance.

Malware often uses the registry for persistence or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots.

  • Root key - The registry is divided into five top-level sections called root keys (sometimes called HKEY)
  • Subkey - Akin to a subfolder within a folder
  • Key - A key is a folder in the registry that can contain additional folders or values
    • The root key and subkey are both keys
  • Value entry - A value entry is an ordered pair with a name and value
  • Value or data - The data stored in a registry entry

Registry Root Keys

  • HKEY_LOCAL_MACHINE (HKLM) - Stores settings that are global to the local machine
    • Contains HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    • This is the key that stores a list of executables that are run at start up
  • HKEY_CURRENT_USER (HKCU) - Stores settings specific to the current user
    • This is a virtual key, stored in HKEY_USERS\SID
    • Where SID is the security identifier of the user currently logged in
  • HKEY_CLASSES ROOT - Stores information defining types
  • HKEY_CURRENT_CONFIG - Stores settings about the current hardware configuration, specifically differences between the current and standard configuration
  • HKEY_USERS - Defines settings for the default user, new user and current user
Common Registry Functions
  • RegOpenKeyEx - Opens a registry for editing and querying
  • RegSetValueEx - Adds a new value to the registry and sets its data
  • RegGetValue - Returns the data for a value entry in the registry

You can use RegEdit to view and edit the registry.

Networking APIs

1646936140.png

Following Malware Execution

DLLs

To store malicious code:

  • Malware often uses a dll to load itself into another process
    • This is because one process can only contain one .exe

By using Windows dlls:

  • Windows dlls contain the functionality to interact with the OS
  • Looking at what dlls are used can help find the functionality of the malware

By using third-party dlls

  • This can provide further insight to what the malware does
    • e.g. if it uses a Mozilla dll instead of the standard Windows API, it might be using functions not found in the Windows API such as encryption

DLLs are similar to EXEs, there’s a flag in the PE to indicate the file is a dll.

Processes

  • Malware can execute outside the current program by creating a new process or modifying an existing one.
    • A process is a program being executed by Windows
  • Each process manages its own resources such as open handles and memory
  • A process contains one or more threads that are executed by the CPU.
  • CreateProcess can be used to create a new process

Threads

Processes are the container for execution, but threads are what the Windows OS executes.

  • Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads
  • A process contains one or more threads, which execute part of the code within a process.
  • Threads within a process all share a memory space but have separate registers and stacks

CreateThread can be used to create new threads

  1. Malware can use CreateThread to load a new malicious library into a process with CreateThread called and the address of LoadLibrary as the start address
  2. Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket.

Services

Another way for malware to execute additional code is by installing it as a service.

  • Windows allows tasks to run without their own processes or threads by using services that run as background applications
    • Code is scheduled and run by the Windows service manager without user input.
  • Services are normally run as SYSTEM or another privileged account
  • Key service functions:
    • OpenSCManager Returns a handle to the service control manager
    • CreateService - Adds a new service to the service control manager
      • Allows the caller to specify whether the service will start automatically at boot time or be started manually
    • StartService Starts the service, only used if service needs to be started manually