65 lines
2.5 KiB
Markdown
65 lines
2.5 KiB
Markdown
# Dynamic Analysis
|
|
|
|
Programs = data structures + algorithms
|
|
|
|
- All programs (including malware) are a series of instructions
|
|
- That get executed by the CPU
|
|
- By observing these instructions as they run, we can see what the program actually does
|
|
|
|
##### Internal Actions
|
|
|
|
- Some of the instructions will cause things to happen within the program
|
|
- Only affecting the data within the program
|
|
- We can analyse this but it requires us to get inside the program and watch what it does internally
|
|
- Using tools like a *debugger*
|
|
- Requires understanding of machine code
|
|
|
|
##### External Actions
|
|
|
|
- Programs also have effects outside the program
|
|
- Can monitor the external actions and get an idea about the programs activity
|
|
- Not just what the program does but also the order the program performs those actions
|
|
|
|
##### Running the Malware
|
|
|
|
Note:
|
|
|
|
- It is important that dynamic analysis is done after the program has been statically analysed
|
|
- This is because the malware can put your system and network at risk
|
|
- Can be tricky to make the malware run
|
|
- If its distributed as a `.exe`, then we can just run it
|
|
- But might do different things based on command line options
|
|
- If its distributed as `.DLL`, then its more complicated
|
|
- Can use `rundll32.exe` to start it and specify the export to call
|
|
- As a last resort you can force the `.dll` to behave as a `.exe` by editing the PE header
|
|
|
|
#### Monitoring with Process Monitor - ProcMon
|
|
|
|
Process Monitor or procmon is an advanced monitoring tool for Windows that provides a way to monitor certain registry, file system, process and thread activity.
|
|
|
|
- Procmon monitors all system calls
|
|
- Because there are so many system calls (around 50,000 per minute) it is import to filter by type
|
|
- Filter by:
|
|
- **Registry** - Tells us how malware installs itself into the registry
|
|
- **File System** - Shows us all the files that the malware creates or config files it uses
|
|
- **Process Activity** - Tells us if the malware spawns any additional processes
|
|
- **Network** - Shows us if the malware is listening on any specific ports
|
|
|
|
#### Comparing Registry Snapshots - RegShot
|
|
|
|
An open-source registry comparison tool that allows you to take and compare two registry snapshots.
|
|
|
|
- We can look for added values
|
|
- A malware has added a new registry key
|
|
- Or modified keys
|
|
- A malware has modified a registry perhaps inserting itself into non-malicious software
|
|
|
|
### General Steps
|
|
|
|
1. Run procmon
|
|
2. Run process explorer
|
|
3. Get an initial snapshot with RegShot
|
|
4. Run the malware
|
|
5. Take another snapshot and compare, also analysing procmon and process explorer.
|
|
|