8.1 KiB
Analysing Malicious Windows Programs
The Windows API
Types and Hungarian Notation
DWORD - 32 bit unsigned integer
WORD - 16 bit unsigned integer
Hungarian notation is where variables are prefixed with their data type e.g. dwSize has prefix dw for DWORD indicating it is a 32 bit unsigned int
| Type and Prefix | Description |
|---|---|
WORD (w) |
A 16 bit unsigned vvalue |
DWORD (dw) |
A double word, 32-bit unsigned value |
Handles (H) |
A reference to an object. The information stored in the handle is no documented, and the handle should be manipulated only by the Windows API |
Long Pointer (LP) |
A pointer to another type e.g. LPByte is a pointer to a byte. Strings are usually prefixed with LP because they are actually pointers. |
| Callback | Represents a function that will be called by the Windows API |
Handles
Handles are items that have been opened or created in the OS, such as a window, process, module, menu, file etc.
- Handles are like pointers in that they refer to an object or memory location
- Unlike pointers handles cannot be used in arithmetic operations
- The only use case is storing it and use it later in a function call
File System Functions
Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system:
CreateFile- used to create and open files. It can open existing files, pipes, streams and I/O devices.ReadFileandWriteFile- used for reading and writing to the contents of files. Both operate on files as a stream.CreateFileMappingandMapViewOfFile- File mappings are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily.CreateFileMappingloads a file from disk into memoryMapViewOfFilereturns a pointer to the base address of the mapping, this can be used to access the file in memory
Special Files
Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like C:\docs)
Shared Files
Sharted files are special files with names that start with \\serverName\share or \\?\serverName\share
- They access directories or files in a shared folder stored on a network.
\\?\prefix tells the OS to disable all string parsing and allows access to longer filenames
Files Accessible via Namespaces
Namespaces can be thought of as a fixed number of folders, each storing different types of objects
- The lowest level namespace is
NTwith the prefix\. - The
NTnamespace has access to all devices, and all other namespaces exist within theNTnamespace
The Win32 device namespace (prefix \\.\) is often used to access physical devices directly and read/write to them like a file.
\\.\PhysicalDisk1to directly access the disk while ignoring its file system- By doing this malware can read and write data to an unallocated sector in the drive without creating a file
- This is very good for avoiding detection
Alternate Data Streams
ADS allows additional data to be addwed to an existing file within NTFS
- The extra data doesn’t show up in a directory listing nor when displaying the contents of the file
- It’s only visible when accessing the stream
- ADS data is named
normalFile.txt:Stream:$DATA
The Windows Registry
The Windows registry is used to store OS and program configuration information, such as settings and options.
In early versions of windows the registry was just a hierarchy of .ini files to improve performance.
Malware often uses the registry for persistence or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots.
- Root key - The registry is divided into five top-level sections called root keys (sometimes called
HKEY) - Subkey - Akin to a subfolder within a folder
- Key - A key is a folder in the registry that can contain additional folders or values
- The root key and subkey are both keys
- Value entry - A value entry is an ordered pair with a name and value
- Value or data - The data stored in a registry entry
Registry Root Keys
HKEY_LOCAL_MACHINE(HKLM) - Stores settings that are global to the local machine- Contains
HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run - This is the key that stores a list of executables that are run at start up
- Contains
HKEY_CURRENT_USER(HKCU) - Stores settings specific to the current user- This is a virtual key, stored in
HKEY_USERS\SID - Where
SIDis the security identifier of the user currently logged in
- This is a virtual key, stored in
HKEY_CLASSES ROOT- Stores information defining typesHKEY_CURRENT_CONFIG- Stores settings about the current hardware configuration, specifically differences between the current and standard configurationHKEY_USERS- Defines settings for the default user, new user and current user
Common Registry Functions
RegOpenKeyEx- Opens a registry for editing and queryingRegSetValueEx- Adds a new value to the registry and sets its dataRegGetValue- Returns the data for a value entry in the registry
You can use RegEdit to view and edit the registry.
Networking APIs
Following Malware Execution
DLLs
To store malicious code:
- Malware often uses a
dllto load itself into another process- This is because one process can only contain one
.exe
- This is because one process can only contain one
By using Windows dlls:
- Windows dlls contain the functionality to interact with the OS
- By looking at what dlls are used can help find the functionality of the malware
By using third-party dlls
- This can provide further insight to what the malware does
- e.g. if it uses a mozilla
dllinstead of the standard windows api, it might be usiing functions not found in the windows api such as encryption
- e.g. if it uses a mozilla
DLLs are similar to EXEs, there’s a flag in the PE to indicate the file is a dll.
Processes
- Malware can execute outside the current program by creating a new process or modifying an existing one.
- A process is a program being executed by Windows
- Each process manages its own resources such as open handles and memory
- A process contains one or more threads that are executed by the CPU.
CreateProcesscan be used to create a new process
Threads
Processes are the container for execution, but threads are what the windows OS executes.
- Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads
- A process contains one or more threads, which execute part of the code within a process.
- Threads within a process all share a memory space but have seperate registers and stack
CreateThread can be used to create new threads
- Malware can use
CreateThreadto load a new malicious library into a process withCreateThreadcalled and the address ofLoadLibraryas the start address - Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket.
Services
Another way for malware to execute additional code is by installing it as a service.
- Windows allows tasks to run without their own processes or threads by using services that run as background applications
- Code is scheduled and run by the Windows service manager without user input.
- Services are normally run as
SYSTEMor another privileged account - Key service functions:
OpenSCManagerReturns a handle to the service control managerCreateService- Adds a new service to the service control manager- Allows caller to specify whether the service will start automatically at boot time, or started manually
StartServiceStarts the service, only used if service needs to be started manually
