Skip to main content

Posts

Malware Analysis Using Volatility - Part 2

THE ARCHITECTURE OF THE GUI WINDOWS SYSTEM FROM THE FORENSICS POINT OF  VIEW  In this module:     ➡ The use of the Volatility plugins for forensic analysis of the Windows system.     ➡ How extract evidence from a Windows GUI subsystem.     ➡ Try to identify hidden processes.     ➡ Analyzing kernel driver identification.     ➡ Exploring the plugins to collect evidence. To deal with the topics of Module 2 we will explore a classic example of Malware forensics. Let's find out the profile of the memory sample. And from that point we will use some Volatility commands and try to understand the flow the Malware infection causes on the victim machine. We started considering that we don’t have any information about the image that we received to analyze. So, let's use imageinfo (can also use the kdbgscan command) to describe the profile of the operating system associated with this image. Then we use the pslist com...

Malware Analysis Using Volatility - Part 1

Malware Analysis with Volatility Module 1 ➡ How do you capture the image memory of a machine through the use of different      tools ➡ Software Imager Lite 3.1.1 (FTK), Ram Capturer 1.0 (Belkasoft) and Dumpit 1.3.2      (Moonsols). ➡ How to configure your computer environment to use the Volatility. ➡ And the basic use of imageinfo, kdbgscan, pslist, pstree and psscan plugins in the      Volatility (version 2.5). Memory tools for Live Analysis First let's start with the RAM capture tools. In a modern school of live analysis a forensic analyst should have more than one tool at your disposal. Will show the use of memory tools for live analysis. The tools and the file format Imager Lite     ➡ The Imager Lite captures the RAM and saved in a memdump.mem file.     ➡ The Imager doesn't need to be installed on the machine. Dumpit     ➡ The Dumpit saved the output in a PAULO-PC 20160617-213817....

Hacking - Best OF Reverse Engineering - Part24

Android.Bankun And Other Android Obfuscation Tactics: A New Malware Era There’s one variant of Android.Bankun that is particularly interesting to me. When you look at the manifest it doesn’t have even one permission. Even the most simple apps have at least internet permissions. Having no permissions isn’t a red flag for being malicious though. In fact, it may even make you lean towards it being legitimate. However, there is one thing that gives Android.Bankun a red flag though. The package name of com.google.bankun instantly makes me think something is fishy. To the average user the word‚ Google’ is seen as a word to be trusted. This is especially true when it comes to the Android operating system which is of course created by the search engine giant. Malware authors now this and heavily use it to disguise their malicious intent. Mobile threat researchers like myself also know this and end up looking twice whenever we see ‚Google’ being used. Diving into the code, we see a sim...

Hacking - Best OF Reverse Engineering - Part23

Advanced Malware Detection using Memory Forensics Memory Forensics is the analysis of the memory image taken from the running computer. In this article, we will learn how to use Memory Forensic Toolkits such as Volatility to analyze the memory artifacts with practical real life forensics scenarios. Memory forensics plays an important role in investigations and incident response. It can help in extracting forensics artifacts from a computer’s memory like running process, network connections, loaded modules etc. It can also help in unpacking, rootkit detection and reverse engineering. Steps in memory Forensics Below are the list of steps involved in memory forensics. Memory Acquisition This step involves dumping the memory of the target machine. On the physical machine you can use tools like Win32dd/Win64dd, Memoryze, DumpIt, FastDump. Whereas on the virtual machine, acquiring the memory image is easy, you can do it by suspending the VM and grabbing the “.vmem” file. Me...

Hacking - Best OF Reverse Engineering - Part22

Next Generation of Automated Malware Analysis and Detection In the last ten years, malicious software – malware – has become increasingly sophisticated, both in terms of how it is used and what it can do. This rapid evolution of malware is essentially a cyber “arms race” run by organizations with geopolitical agendas and profit motives. The resulting losses for victims have run to billions of dollars. The global move to digitize personal and sensitive information as well as to computerize and interconnect critical infrastructure has far outpaced the capabilities of the security measures that have been put into place. As a result, cyber criminals can act with near impunity as they break into networks to steal data and hijack resources. It is difficult to stop their criminal malware and nearly impossible to track them down after an attack has been perpetrated. What we see is that today’s network defenses are aggressively evaded by malware that is even moderately advanced. Why is t...

Hacking - Best OF Reverse Engineering - Part21

Hybrid Code Analysis versus State of the Art Android Backdoors Mobile Malware is evolving… can the good guys beat the new challenges? Mainstream usage of handheld devices running the popular Android OS is the main stimulation for mobile malware evolution. The rapid growth of malware and infected Android application package (APK) files found on the many app stores is an important new challenge for mobile IT security. Sophisticated anti-reverse engineering techniques, such as encryption and heavy obfuscation, are becoming malware industry standard. In June, an unofficial, but popular app store released more than 50.000 new applications (AppBrain, 2013). The Figure 1 outlines the rising trend of new application releases on AppBrain with a growing portion of low quality applications. About 13 billion APK file download have been registered worldwide up until today, while this is counting only the official app stores (AndroLib, 2013). The problem we face today i...