2.6 KiB
2.6 KiB
Dynamic Analysis
Programs = data structures + algorithms
- All programs (including malware) are a series of instructions
- That get executed by the CPU
- By observing these instructions as they run, we can see what the program actually does
Internal Actions
- Some of the instructions will cause things to happen within the program
- Only affecting the data within the program
- We can analyse this but it requires us to get inside the program and watch what it does internally
- Using tools like a debugger
- Requires understanding of machine code
External Actions
- Programs also have effects outside the program
- Can monitor the external actions and get an idea about the program’s activity
- Not just what the program does but also the order the program performs those actions
Running the Malware
Note:
- It is important that dynamic analysis is done after the program has been statically analysed
- This is because the malware can put your system and network at risk
- Can be tricky to make the malware run
- If it’s distributed as an
.exe, then we can just run it - But might do different things based on command line options
- If it’s distributed as a
.DLL, then it’s more complicated - Can use
rundll32.exeto start it and specify the export to call - As a last resort you can force the
.dllto behave as an.exeby editing the PE header
Monitoring with Process Monitor - ProcMon
Process Monitor or procmon is an advanced monitoring tool for Windows that provides a way to monitor certain registry, file system, process and thread activity.
- Procmon monitors all system calls
- Because there are so many system calls (around 50,000 per minute) it is important to filter by type
- Filter by:
- Registry - Tells us how malware installs itself into the registry
- File System - Shows us all the files that the malware creates or config files it uses
- Process Activity - Tells us if the malware spawns any additional processes
- Network - Shows us if the malware is listening on any specific ports
Comparing Registry Snapshots - RegShot
An open-source registry comparison tool that allows you to take and compare two registry snapshots.
- We can look for added values
- Malware has added a new registry key
- Or modified keys
- Malware has modified a registry, perhaps inserting itself into non-malicious software
General Steps
- Run procmon
- Run process explorer
- Get an initial snapshot with RegShot
- Run the malware
- Take another snapshot and compare, also analysing procmon and process explorer.