Files
notes/docs/lectures/malware/05_windows_analysis.md
T

164 lines
8.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Analysing Malicious Windows Programs
## The Windows API
##### Types and Hungarian Notation
`DWORD` - 32 bit unsigned integer
`WORD` - 16 bit unsigned integer
Hungarian notation is where variables are prefixed with their data type e.g. `dwSize` has prefix `dw` for `DWORD` indicating it is a 32 bit unsigned int
| Type and Prefix | Description |
| ------------------- | ------------------------------------------------------------ |
| `WORD` (`w`) | A 16 bit unsigned vvalue |
| `DWORD` (`dw`) | A double word, 32-bit unsigned value |
| Handles (`H`) | A reference to an object. The information stored in the handle is no documented, and the handle should be manipulated only by the Windows API |
| Long Pointer (`LP`) | A pointer to another type e.g. `LPByte` is a pointer to a byte. Strings are usually prefixed with `LP` because they are actually pointers. |
| Callback | Represents a function that will be called by the Windows API |
##### Handles
*Handles* are items that have been opened or created in the OS, such as a window, process, module, menu, file etc.
- Handles are like pointers in that they refer to an object or memory location
- Unlike pointers handles cannot be used in arithmetic operations
- The only use case is storing it and use it later in a function call
##### File System Functions
Most malware will interact with the system by creating or modifying files. Microsoft provides several functions for accessing the file system:
- `CreateFile` - used to create and open files. It can open existing files, pipes, streams and I/O devices.
- `ReadFile` and `WriteFile` - used for reading and writing to the contents of files. Both operate on files as a stream.
- `CreateFileMapping` and `MapViewOfFile` - *File mappings* are commonly used by malware writers because they allow a file to be loaded into memory and manipulated easily.
- `CreateFileMapping` loads a file from disk into memory
- `MapViewOfFile` returns a pointer to the base address of the mapping, this can be used to access the file in memory
##### Special Files
Windows has a number of file types that can be accessed much like regular files, but that are not accessed by their drive letter and folder (like `C:\docs`)
###### Shared Files
Sharted files are special files with names that start with `\\serverName\share` or `\\?\serverName\share`
- They access directories or files in a shared folder stored on a network.
- `\\?\` prefix tells the OS to disable all string parsing and allows access to longer filenames
###### Files Accessible via Namespaces
*Namespaces* can be thought of as a fixed number of folders, each storing different types of objects
- The lowest level namespace is `NT` with the prefix `\.`
- The `NT` namespace has access to all devices, and all other namespaces exist within the `NT` namespace
The `Win32` device namespace (prefix `\\.\`) is often used to access physical devices directly and read/write to them like a file.
- `\\.\PhysicalDisk1` to directly access the disk while ignoring its file system
- By doing this malware can read and write data to an unallocated sector in the drive without creating a file
- This is very good for avoiding detection
###### Alternate Data Streams
ADS allows additional data to be addwed to an existing file within `NTFS`
- The extra data doesn’t show up in a directory listing nor when displaying the contents of the file
- It’s only visible when accessing the stream
- ADS data is named `normalFile.txt:Stream:$DATA`
## The Windows Registry
The *Windows registry* is used to store OS and program configuration information, such as settings and options.
In early versions of windows the registry was just a hierarchy of `.ini` files to improve performance.
Malware often uses the registry for *persistence* or configuration data. The malware adds entries into the registry that will allow it to run automatically when the computer boots.
- **Root key** - The registry is divided into five top-level sections called *root keys* (sometimes called `HKEY`)
- **Subkey** - Akin to a subfolder within a folder
- **Key** - A key is a folder in the registry that can contain additional folders or values
- The root key and subkey are both keys
- **Value entry** - A *value entry* is an ordered pair with a name and value
- **Value or data** - The data stored in a registry entry
#### Registry Root Keys
- `HKEY_LOCAL_MACHINE` (`HKLM`) - Stores settings that are global to the local machine
- Contains ` HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
- This is the key that stores a list of executables that are run at start up
- `HKEY_CURRENT_USER` (`HKCU`) - Stores settings specific to the current user
- This is a virtual key, stored in `HKEY_USERS\SID`
- Where `SID` is the security identifier of the user currently logged in
- `HKEY_CLASSES ROOT` - Stores information defining types
- `HKEY_CURRENT_CONFIG` - Stores settings about the current hardware configuration, specifically differences between the current and standard configuration
- `HKEY_USERS` - Defines settings for the default user, new user and current user
##### Common Registry Functions
- `RegOpenKeyEx` - Opens a registry for editing and querying
- `RegSetValueEx` - Adds a new value to the registry and sets its data
- `RegGetValue` - Returns the data for a value entry in the registry
You can use RegEdit to view and edit the registry.
### Networking APIs
![1646936140.png](img/1646936140.png)
## Following Malware Execution
#### DLLs
To store malicious code:
- Malware often uses a `dll` to load itself into another process
- This is because one process can only contain one `.exe`
By using Windows `dll`s:
- Windows dlls contain the functionality to interact with the OS
- By looking at what dlls are used can help find the functionality of the malware
By using third-party `dll`s
- This can provide further insight to what the malware does
- e.g. if it uses a mozilla `dll` instead of the standard windows api, it might be usiing functions not found in the windows api such as encryption
`DLL`s are similar to `EXE`s, there’s a flag in the PE to indicate the file is a dll.
#### Processes
- Malware can execute outside the current program by creating a new process or modifying an existing one.
- A process is a program being executed by Windows
- Each process manages its own resources such as open handles and memory
- A process contains one or more threads that are executed by the CPU.
- `CreateProcess` can be used to create a new process
#### Threads
Processes are the container for execution, but *threads* are what the windows OS executes.
- Threads are independent sequences of instructions that are executed by the CPU without waiting for other threads
- A process contains one or more threads, which execute part of the code within a process.
- Threads within a process all share a memory space but have seperate registers and stack
`CreateThread` can be used to create new threads
1. Malware can use `CreateThread` to load a new malicious library into a process with `CreateThread` called and the address of `LoadLibrary` as the start address
2. Malware can create two new threads: one to listen on a socket or port and then output that to standard input of a process, and the other to read from standard output and send that to a socket.
#### Services
Another way for malware to execute additional code is by installing it as a *service*.
- Windows allows tasks to run without their own processes or threads by using services that run as background applications
- Code is scheduled and run by the Windows service manager without user input.
- Services are normally run as `SYSTEM` or another privileged account
- Key service functions:
- `OpenSCManager` Returns a handle to the service control manager
- `CreateService` - Adds a new service to the service control manager
- Allows caller to specify whether the service will start automatically at boot time, or started manually
- `StartService` Starts the service, only used if service needs to be started manually