64 lines
2.6 KiB
Markdown
64 lines
2.6 KiB
Markdown
# Dynamic Analysis
|
||
|
||
Programs = data structures + algorithms
|
||
|
||
- All programs (including malware) are a series of instructions
|
||
- That get executed by the CPU
|
||
- By observing these instructions as they run, we can see what the program actually does
|
||
|
||
##### Internal Actions
|
||
|
||
- Some of the instructions will cause things to happen within the program
|
||
- Only affecting the data within the program
|
||
- We can analyse this but it requires us to get inside the program and watch what it does internally
|
||
- Using tools like a *debugger*
|
||
- Requires understanding of machine code
|
||
|
||
##### External Actions
|
||
|
||
- Programs also have effects outside the program
|
||
- Can monitor the external actions and get an idea about the program’s activity
|
||
- Not just what the program does but also the order the program performs those actions
|
||
|
||
##### Running the Malware
|
||
|
||
Note:
|
||
|
||
- It is important that dynamic analysis is done after the program has been statically analysed
|
||
- This is because the malware can put your system and network at risk
|
||
- Can be tricky to make the malware run
|
||
- If it’s distributed as an `.exe`, then we can just run it
|
||
- But might do different things based on command line options
|
||
- If it’s distributed as a `.DLL`, then it’s more complicated
|
||
- Can use `rundll32.exe` to start it and specify the export to call
|
||
- As a last resort you can force the `.dll` to behave as an `.exe` by editing the PE header
|
||
|
||
#### Monitoring with Process Monitor - ProcMon
|
||
|
||
Process Monitor or procmon is an advanced monitoring tool for Windows that provides a way to monitor certain registry, file system, process and thread activity.
|
||
|
||
- Procmon monitors all system calls
|
||
- Because there are so many system calls (around 50,000 per minute) it is important to filter by type
|
||
- Filter by:
|
||
- **Registry** - Tells us how malware installs itself into the registry
|
||
- **File System** - Shows us all the files that the malware creates or config files it uses
|
||
- **Process Activity** - Tells us if the malware spawns any additional processes
|
||
- **Network** - Shows us if the malware is listening on any specific ports
|
||
|
||
#### Comparing Registry Snapshots - RegShot
|
||
|
||
An open-source registry comparison tool that allows you to take and compare two registry snapshots.
|
||
|
||
- We can look for added values
|
||
- Malware has added a new registry key
|
||
- Or modified keys
|
||
- Malware has modified a registry, perhaps inserting itself into non-malicious software
|
||
|
||
### General Steps
|
||
|
||
1. Run procmon
|
||
2. Run process explorer
|
||
3. Get an initial snapshot with RegShot
|
||
4. Run the malware
|
||
5. Take another snapshot and compare, also analysing procmon and process explorer.
|