Files
notes/docs/lectures/malware/02_dynamic_analysis.md
T
2026-10-04 15:24:17 +01:00

64 lines
2.6 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Dynamic Analysis
Programs = data structures + algorithms
- All programs (including malware) are a series of instructions
- That get executed by the CPU
- By observing these instructions as they run, we can see what the program actually does
##### Internal Actions
- Some of the instructions will cause things to happen within the program
- Only affecting the data within the program
- We can analyse this but it requires us to get inside the program and watch what it does internally
- Using tools like a *debugger*
- Requires understanding of machine code
##### External Actions
- Programs also have effects outside the program
- Can monitor the external actions and get an idea about the program’s activity
- Not just what the program does but also the order the program performs those actions
##### Running the Malware
Note:
- It is important that dynamic analysis is done after the program has been statically analysed
- This is because the malware can put your system and network at risk
- Can be tricky to make the malware run
- If it’s distributed as an `.exe`, then we can just run it
- But might do different things based on command line options
- If it’s distributed as a `.DLL`, then it’s more complicated
- Can use `rundll32.exe` to start it and specify the export to call
- As a last resort you can force the `.dll` to behave as an `.exe` by editing the PE header
#### Monitoring with Process Monitor - ProcMon
Process Monitor or procmon is an advanced monitoring tool for Windows that provides a way to monitor certain registry, file system, process and thread activity.
- Procmon monitors all system calls
- Because there are so many system calls (around 50,000 per minute) it is important to filter by type
- Filter by:
- **Registry** - Tells us how malware installs itself into the registry
- **File System** - Shows us all the files that the malware creates or config files it uses
- **Process Activity** - Tells us if the malware spawns any additional processes
- **Network** - Shows us if the malware is listening on any specific ports
#### Comparing Registry Snapshots - RegShot
An open-source registry comparison tool that allows you to take and compare two registry snapshots.
- We can look for added values
- Malware has added a new registry key
- Or modified keys
- Malware has modified a registry, perhaps inserting itself into non-malicious software
### General Steps
1. Run procmon
2. Run process explorer
3. Get an initial snapshot with RegShot
4. Run the malware
5. Take another snapshot and compare, also analysing procmon and process explorer.