2.5 KiB
2.5 KiB
Dynamic Analysis
Programs = data structures + algorithms
- All programs (including malware) are a series of instructions
- That get executed by the CPU
- By observing these instructions as they run, we can see what the program actually does
Internal Actions
- Some of the instructions will cause things to happen within the program
- Only affecting the data within the program
- We can analyse this but it requires us to get inside the program and watch what it does internally
- Using tools like a debugger
- Requires understanding of machine code
External Actions
- Programs also have effects outside the program
- Can monitor the external actions and get an idea about the programs activity
- Not just what the program does but also the order the program performs those actions
Running the Malware
Note:
- It is important that dynamic analysis is done after the program has been statically analysed
- This is because the malware can put your system and network at risk
- Can be tricky to make the malware run
- If its distributed as a
.exe, then we can just run it - But might do different things based on command line options
- If its distributed as
.DLL, then its more complicated - Can use
rundll32.exeto start it and specify the export to call - As a last resort you can force the
.dllto behave as a.exeby editing the PE header
Monitoring with Process Monitor - ProcMon
Process Monitor or procmon is an advanced monitoring tool for Windows that provides a way to monitor certain registry, file system, process and thread activity.
- Procmon monitors all system calls
- Because there are so many system calls (around 50,000 per minute) it is import to filter by type
- Filter by:
- Registry - Tells us how malware installs itself into the registry
- File System - Shows us all the files that the malware creates or config files it uses
- Process Activity - Tells us if the malware spawns any additional processes
- Network - Shows us if the malware is listening on any specific ports
Comparing Registry Snapshots - RegShot
An open-source registry comparison tool that allows you to take and compare two registry snapshots.
- We can look for added values
- A malware has added a new registry key
- Or modified keys
- A malware has modified a registry perhaps inserting itself into non-malicious software
General Steps
- Run procmon
- Run process explorer
- Get an initial snapshot with RegShot
- Run the malware
- Take another snapshot and compare, also analysing procmon and process explorer.