Saltar al contenido principal
MALWARE ANALYSIS
THE ART OF BEING FRIEND OF
MALWARE.
TOUHAMI KASBAOUI!
• DEVELOPER CYBER SECURITY SOLUTIONS, PURPLE
TEAM.
• NOCONAME SPEAKER
• ZERODIUM HUNTER
• BUG BOUNTY HUNTER.
• DEVELOPER APT ATTACKS (MILITARY COMPANIES)
• BLEU TEAM DEVELOPER SOLUTIONS (0BTEMOS
TRACKER, BLACKCODE)
• …
$WHOAMI
MALWARE ANALYSIS THE BASICS
Class Description
Virus Code that propagates (replicates) across systems with user intervention
Worm
Code that self-propagates/replicates across systems without requiring
user intervention
Bot Automated process that interacts with other network services
Trojan Malware that is often disguised as legitimate software
Ransomware
Malware that holds the victim's data hostage by cryptography or other
means
Rootkit Masks its existence or the existence of other software
Backdoor
Enables a remote attacker to have access to or send commands to a
compromised computer
RAT Remote Access Trojan, similar to a backdoor
Info Stealer Steals victims information, passwords, or other personal data
HackTool
Admin tools or programs that may be used by hackers to attack
computer systems and networks. These programs are not generally
malicious
Hoax
Program may deliver a false warning about a computer virus or install
a fake AV
Dropper/Downloader Designed to "install" or download some sort of malware
Adware
Automatically renders advertisements in order to generate revenue for
its author.
PUP/PUA
Potentially Unwanted Program, sometimes added to a system without
the user's knowledge or approval
HOW DID IT START ?
• 1989: AIDS Trojan, first case of ransomware
• 2005: Gpcode (PGPCoder)
• 2009/2010: WinLock
• 2012:ACCDFISA, Urausy, Reveton
• 2013: CryptoLocker
• 2014: CTB-Locker (Citroni), torrentlocker, CryptoWall
• 2015:Mobile Ransomware (on Android), such as Fusob
• 2016: Locky, ‘Open Source’ Ransomware such as Eda2, Hidden tear
• 2017: WannaCry (May), NotPetya(June), BadRabbit(October)
• 2018/2019: GandCrab, Deja-Vu
• 2020/2021: DarkSide, SaveTheQueen, Thanatos
CRYPTO-LOCKER
• Intoroduction the end of roguware (fake anti-virus)
• Innovative …
• Instpirational …
• … And very annoying ☺
• Many assumed that any form of cryptographic
ransomware (cryptoware) is CryptoLocker however
this was one ransomware variant. It has been dead
since 2014
HOW DOES ONE GET MALWARE ? THE BAD WAY
• Phishing or spear-phishing
• Exploit kits
• Drive-by download
• USB drive or other removable media
• Network (Shares, SMB)
• Manual installation (RDP, VNC, Team Viewer, … )
• Watering hole (Strategic Web Compromise)
• Other Malware that downloads and/or install ‘Companions’
• Exploit security vulnerability (RCE , 0day zero click or one click)
HOW DOES ONE GET MALWARE ? FOR ANALYSIS PURPOSES
• Malware Samples Sources for researchers
• http://tracker.0btemoslab.com/tracker/ (infected/infected)
• List of malware sources:
• https://github.com/fabacab/awesome-malware (open source and black box)
• Be master of funding legit samples from live honeypots by checking only the
MD5 hash with google.com ☺
• Track back from the end to the start by looking from the source c&c
• http://tracker.0btemoslab.com
ANALYZING MALWARE: STATIC VS DYNAMIC
• Static: do not run the malware, look at static properties
• Can you think of tools, or what could considered static properties?
• Dynamic: run the malware, and examine onwards
• Can you think of tools, or what could only be discovered by running the malware?
• Why Not BOTH ?
ANALYZING MALWARE: STATIC VS DYNAMIC
• Hi! Just giving you that reminder,
• What is Reverse Engineering?
• Game Plan
STATIC MALWARE ANALYSIS: PRIMER
First of, consider the type of a file, Is it a (n) …
• Executable? EXE, COM, SCR, PIF, DLL
• Strins, compile time, imports, sections …
• Image? PNG, BMP, JPG, GIF
• Steganography, hidden content, creator/creation date, …
• Office file? DOC/DOCX, XLS/ XLSX, RTF
• Creator/Creation date, embedded content, filename, …
• Adobe file: PDF, SWF/FWS
• Creator/Creation date, embedded content, filename, …
• Archive: ZIP, RAR, 7z, ISO
• Creation date, contents, …
STATIC MALWARE ANALYSIS: TOOLS
It is important to have proper toolbox, or toolset
• Exectable ?
• ExeinfoP, Detect it Easy (DIE), Peviewer (RogueKillerPE)
• Office document?
• OLETools, oledump, OfficeMalscanner, QuickSand
• Adobe Document?
• Pdfid, pdf-parser, PDF Stream Dumper
• Additionally: Strings2, FLOSS, and … calculate hash ! (MD5, SHA1, SHA256)
STATIC MALWARE ANALYSIS: TOOLS
It is important to have proper toolbox, or toolset
• Exectable ?
• ExeinfoP, Detect it Easy (DIE), Peviewer (RogueKillerPE)
• Office document?
• OLETools, oledump, OfficeMalscanner, QuickSand
• Adobe Document?
• Pdfid, pdf-parser, PDF Stream Dumper
• Additionally: Strings2, FLOSS, and … calculate hash ! (MD5, SHA1, SHA256)
• Usually and necessary: Wireshark, Fiddler, x64db, IDA, Ghidra, ProcMon + Process Hacker
STATIC MALWARE ANALYSIS: PE WHAT IN A FILE?
Short for PE – portable executable and Common Object File format Specification.
NT HEADER
PE Signature
File Header
Optional Header
Optional Header
Section Directory
Sections
.text
.data
.rdata
.reloc
.rsrc
.debug
Section Headers
STATIC MALWARE ANALYSIS: WINDOWS ARCHITECTURE
STATIC MALWARE ANALYSIS: ANATOMY OF A WINDOWS
PE C PROGRAM
STATIC MALWARE ANALYSIS: OPCODES AND
INSTRUCTIONS
•Data Movement/Access
•Arithmetic / Logic
•Control-Flow
STATIC MALWARE ANALYSIS: OPCODES AND
INSTRUCTIONS
Register Description
SS Stack Segment, Pointer to the stack
CS Code Segment, Pointer to the code
DS Data Segment, Pointer to the data
ES Extra Segment, Pointer to extra data
FS
F Segment, Pointer to more extra
data
GS
G Segment, Pointer to still more extra
data
STATIC MALWARE ANALYSIS: REGISTERS
Register Description
EAX Accumulator Register
EBX Base Register
ECX Counter Register
EDX Data Register
ESI Source Index
EDI Destination Index
EBP Base Pointer
ESP Stack Pointer
STATIC MALWARE ANALYSIS: INSTRUCTION POINTER
Register Description
EAX Accumulator Register
EBX Base Register
ECX Counter Register
EDX Data Register
ESI Source Index
EDI Destination Index
EBP Base Pointer
ESP Stack Pointer
STATIC MALWARE ANALYSIS: PACKED MALWARE
•Themida
•Armadillo
•ASPack
•ASPR (ASProtect)
•BoxedApp Packer
•CExe
•dotBundle
•Enigma Protector
•EXE Bundle
•EXE Stealth
•eXPressor
•FSG
•kkrunchy
•MEW
•MPRESS
•Obsidium
•PESpin
•Petite
•RLPack Basic
•Smart Packer Pro
•Themida
•UPX
•VMProtect
•XComp/XPack
STATIC MALWARE ANALYSIS: OBFUSCATION
STATIC MALWARE ANALYSIS: OBFUSCATION
FOLLOW ME
DYNAMIC MALWARE ANALYSIS
DYNAMIC MALWARE ANALYSIS: PRIMER
•You have two different ways of doing dynamic analysis:
•Do it yourself: Run the malware in a VM
•Manual dynamic analysis
• Use a sandbox: let a sandbox take care of the malware
• Authomatic dynamic analysis
DYNAMIC MALWARE ANALYSIS: ONLINE SANDBOX
•You have for online sandbox:
•Virustotal
•Any.run
•malwr.com
•Reverse.it
•Hybird-analysis.com
•Joe sandbox
DYNAMIC MALWARE ANALYSIS: ONLINE SANDBOX
•You have for online sandbox:
•Virustotal
•Any.run
•malwr.com
•Reverse.it
•Hybird-analysis.com
•Joe sandbox
Threat attack existed in Morocco guess what is it ?
THREAT X IN MOROCCO !
Threat attack existed in Morocco guess what is it ?
THREAT X IN MOROCCO !
90% of attacks from Password info stealer!
THREAT X IN MOROCCO !
HOW I CAN PROVE IT ?
THREAT X IN MOROCCO !
OUR Intelligence TRACKER DETECTED AROUND 180GB LEAKED
related to MA domains and personal information.
THREAT X IN MOROCCO !
320+ Spammer identified from the gathered data and c&c checks in
Morocco.
THREAT X IN MOROCCO !
We have some people from ensias.um5.ac.ma
THREAT X IN MOROCCO !
THREAT X IN MOROCCO !
Did this all what we have ?
THREAT X IN MOROCCO !
NO
THREAT X IN MOROCCO !
ATM MALWARE GATHERED FROM MOROCCANS ISP’s
TECHNICAL DETAILS: ATM DISPENSE MALWARE
ATM MALWARE GATHERED FROM MOROCCANS ISP’s
TECHNICAL DETAILS: ATM DISPENSE MALWARE
ATM MALWARE GATHERED FROM MOROCCANS ISP’s
TECHNICAL DETAILS: ATM DISPENSE MALWARE
ATM MALWARE GATHERED FROM MOROCCANS ISP’s
TECHNICAL DETAILS: ATM DISPENSE MALWARE
ATM MALWARE GATHERED FROM MOROCCANS ISP’s
TECHNICAL DETAILS: ATM DISPENSE MALWARE
Getting ready to next war.
THE PURPOSE FROM THESE 2 THREAT
Q/A
THE PURPOSE FROM THESE 2 THREATS