164 lines
8.1 KiB
Markdown
164 lines
8.1 KiB
Markdown
# Analysing Malicious Windows Programs
|
||
|
||
## The Windows API
|
||
|
||
##### Types and Hungarian Notation
|
||
|
||
`DWORD` - 32-bit unsigned integer
|
||
|
||
`WORD` - 16-bit unsigned integer
|
||
|
||
Hungarian notation is where variables are prefixed with their data type e.g. `dwSize` has prefix `dw` for `DWORD` indicating it is a 32-bit unsigned int
|
||
|
||
| Type and Prefix | Description |
|
||
| ------------------- | ------------------------------------------------------------ |
|
||
| `WORD` (`w`) | A 16-bit unsigned value |
|
||
| `DWORD` (`dw`) | A double word, 32-bit unsigned value |
|
||
| Handles (`H`) | A reference to an object. The information stored in the handle is not documented, and the handle should be manipulated only by the Windows API |
|
||
| Long Pointer (`LP`) | A pointer to another type e.g. `LPByte` is a pointer to a byte. Strings are usually prefixed with `LP` because they are actually pointers. |
|
||
| Callback | Represents a function that will be called by the Windows API |
|
||
|
||
##### Handles
|
||
|
||
*Handles* are items that have been opened or created in the OS, such as a window, process, module, menu, file etc.
|
||
|
||
- Handles are like pointers in that they refer to an object or memory location
|
||
- Unlike pointers handles cannot be used in arithmetic operations
|
||
- The only use case is storing it and using it later in a function call
|
||
|
||
##### File System Functions
|
||
|
||
Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system:
|
||
|
||
- `CreateFile` - used to create and open files. It can open existing files, pipes, streams and I/O devices.
|
||
- `ReadFile` and `WriteFile` - used for reading and writing to the contents of files. Both operate on files as a stream.
|
||
- `CreateFileMapping` and `MapViewOfFile` - *File mappings* are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily.
|
||
- `CreateFileMapping` loads a file from disk into memory
|
||
- `MapViewOfFile` returns a pointer to the base address of the mapping, this can be used to access the file in memory
|
||
|
||
##### Special Files
|
||
|
||
Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like `C:\docs`)
|
||
|
||
###### Shared Files
|
||
|
||
Shared files are special files with names that start with `\\serverName\share` or `\\?\serverName\share`
|
||
|
||
- They access directories or files in a shared folder stored on a network.
|
||
- `\\?\` prefix tells the OS to disable all string parsing and allows access to longer filenames
|
||
|
||
###### Files Accessible via Namespaces
|
||
|
||
*Namespaces* can be thought of as a fixed number of folders, each storing different types of objects
|
||
|
||
- The lowest level namespace is `NT` with the prefix `\.`
|
||
- The `NT` namespace has access to all devices, and all other namespaces exist within the `NT` namespace
|
||
|
||
The `Win32` device namespace (prefix `\\.\`) is often used to access physical devices directly and read/write to them like a file.
|
||
|
||
- `\\.\PhysicalDisk1` to directly access the disk while ignoring its file system
|
||
- By doing this malware can read and write data to an unallocated sector in the drive without creating a file
|
||
- This is very good for avoiding detection
|
||
|
||
###### Alternate Data Streams
|
||
|
||
ADS allows additional data to be added to an existing file within `NTFS`
|
||
|
||
- The extra data doesn’t show up in a directory listing nor when displaying the contents of the file
|
||
- It’s only visible when accessing the stream
|
||
- ADS data is named `normalFile.txt:Stream:$DATA`
|
||
|
||
## The Windows Registry
|
||
|
||
The *Windows registry* is used to store OS and program configuration information, such as settings and options.
|
||
|
||
In early versions of Windows the registry was just a hierarchy of `.ini` files to improve performance.
|
||
|
||
Malware often uses the registry for *persistence* or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots.
|
||
|
||
- **Root key** - The registry is divided into five top-level sections called *root keys* (sometimes called `HKEY`)
|
||
- **Subkey** - Akin to a subfolder within a folder
|
||
- **Key** - A key is a folder in the registry that can contain additional folders or values
|
||
- The root key and subkey are both keys
|
||
- **Value entry** - A *value entry* is an ordered pair with a name and value
|
||
- **Value or data** - The data stored in a registry entry
|
||
|
||
#### Registry Root Keys
|
||
|
||
- `HKEY_LOCAL_MACHINE` (`HKLM`) - Stores settings that are global to the local machine
|
||
- Contains ` HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
|
||
- This is the key that stores a list of executables that are run at start up
|
||
- `HKEY_CURRENT_USER` (`HKCU`) - Stores settings specific to the current user
|
||
- This is a virtual key, stored in `HKEY_USERS\SID`
|
||
- Where `SID` is the security identifier of the user currently logged in
|
||
- `HKEY_CLASSES ROOT` - Stores information defining types
|
||
- `HKEY_CURRENT_CONFIG` - Stores settings about the current hardware configuration, specifically differences between the current and standard configuration
|
||
- `HKEY_USERS` - Defines settings for the default user, new user and current user
|
||
|
||
##### Common Registry Functions
|
||
|
||
- `RegOpenKeyEx` - Opens a registry for editing and querying
|
||
- `RegSetValueEx` - Adds a new value to the registry and sets its data
|
||
- `RegGetValue` - Returns the data for a value entry in the registry
|
||
|
||
You can use RegEdit to view and edit the registry.
|
||
|
||
### Networking APIs
|
||
|
||

|
||
|
||
## Following Malware Execution
|
||
|
||
#### DLLs
|
||
|
||
To store malicious code:
|
||
|
||
- Malware often uses a `dll` to load itself into another process
|
||
- This is because one process can only contain one `.exe`
|
||
|
||
By using Windows `dll`s:
|
||
|
||
- Windows dlls contain the functionality to interact with the OS
|
||
- Looking at what dlls are used can help find the functionality of the malware
|
||
|
||
By using third-party `dll`s
|
||
|
||
- This can provide further insight to what the malware does
|
||
- e.g. if it uses a Mozilla `dll` instead of the standard Windows API, it might be using functions not found in the Windows API such as encryption
|
||
|
||
`DLL`s are similar to `EXE`s, there’s a flag in the PE to indicate the file is a dll.
|
||
|
||
#### Processes
|
||
|
||
- Malware can execute outside the current program by creating a new process or modifying an existing one.
|
||
- A process is a program being executed by Windows
|
||
- Each process manages its own resources such as open handles and memory
|
||
- A process contains one or more threads that are executed by the CPU.
|
||
- `CreateProcess` can be used to create a new process
|
||
|
||
#### Threads
|
||
|
||
Processes are the container for execution, but *threads* are what the Windows OS executes.
|
||
|
||
- Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads
|
||
- A process contains one or more threads, which execute part of the code within a process.
|
||
- Threads within a process all share a memory space but have separate registers and stacks
|
||
|
||
`CreateThread` can be used to create new threads
|
||
|
||
1. Malware can use `CreateThread` to load a new malicious library into a process with `CreateThread` called and the address of `LoadLibrary` as the start address
|
||
2. Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket.
|
||
|
||
#### Services
|
||
|
||
Another way for malware to execute additional code is by installing it as a *service*.
|
||
|
||
- Windows allows tasks to run without their own processes or threads by using services that run as background applications
|
||
- Code is scheduled and run by the Windows service manager without user input.
|
||
- Services are normally run as `SYSTEM` or another privileged account
|
||
- Key service functions:
|
||
- `OpenSCManager` Returns a handle to the service control manager
|
||
- `CreateService` - Adds a new service to the service control manager
|
||
- Allows the caller to specify whether the service will start automatically at boot time or be started manually
|
||
- `StartService` Starts the service, only used if service needs to be started manually
|