al-khaser ist eine PoC-„Malware“-Anwendung mit guten Absichten, die darauf abzielt, Ihr Anti-Malware-System zu testen.
Sie führt eine Reihe typischer Malware-Tricks aus, um zu sehen, ob Sie unter dem Radar bleiben.
Verwendung
root@kitploit:~
$ ./al-khaser.exe -h
Usage: al-khaser.exe [OPTIONS]
Options:
--check <type> Enable specific check(s). Can be used multiple times. Valid types are:
TLS (Thread Local Storage callback checks)
DEBUG (Anti-debugging checks)
INJECTION (Code injection checks)
GEN_SANDBOX (Generic sandbox checks)
VBOX (VirtualBox detection)
VMWARE (VMware detection)
VPC (Virtual PC detection)
QEMU (QEMU detection)
KVM (KVM detection)
XEN (Xen detection)
WINE (Wine detection)
PARALLELS (Parallels detection)
HYPERV (Hyper-V detection)
CODE_INJECTIONS (Additional code injection techniques)
TIMING_ATTACKS (Timing/sleep-based sandbox evasion)
DUMPING_CHECK (Dumping memory/process checks)
ANALYSIS_TOOLS (Analysis tools detection)
ANTI_DISASSM (Anti-disassembly checks)
--sleep <seconds> Set sleep/delay duration in seconds (default: 600).
--delay <seconds> Alias for --sleep.
-h, --help Show this help message and exit.
Examples:
al-khaser.exe --check DEBUG --check TIMING_ATTACKS --sleep 30
al-khaser.exe --check VMWARE --check QEMU
al-khaser.exe --sleep 30
Download
Sie können vorgefertigte Binärdateien (x86, x64) von der Releases-Seite dieses Projekts herunterladen. Das Passwort für die 7zs finden Sie hier.
Mögliche Verwendungen
Sie entwickeln ein Anti-Debug-Plugin und möchten dessen Effektivität überprüfen.
Sie möchten sicherstellen, dass Ihre Sandbox-Lösung ausreichend versteckt ist.
Oder Sie möchten sicherstellen, dass Ihre Malware-Analyseumgebung gut verborgen ist.
Wenn Sie auf Anti-Analyse-Tricks stoßen, die Sie in Malware gesehen haben, zögern Sie bitte nicht, einen Beitrag zu leisten.
Funktionen
Anti-Debugging-Angriffe
IsDebuggerPresent
CheckRemoteDebuggerPresent
Process Environment Block (BeingDebugged)
Process Environment Block (NtGlobalFlag)
ProcessHeap (Flags)
ProcessHeap (ForceFlags)
Low Fragmentation Heap (LFH)
NtQueryInformationProcess (ProcessDebugPort)
NtQueryInformationProcess (ProcessDebugFlags)
NtQueryInformationProcess (ProcessDebugObject)
WudfIsAnyDebuggerPresent
WudfIsKernelDebuggerPresent
WudfIsUserDebuggerPresent
NtSetInformationThread (HideThreadFromDebugger)
NtQueryObject (ObjectTypeInformation)
NtQueryObject (ObjectAllTypesInformation)
CloseHanlde (NtClose) Invalide Handle
SetHandleInformation (Protected Handle)
UnhandledExceptionFilter
OutputDebugString (GetLastError())
Hardware Breakpoints (SEH / GetThreadContext)
Software Breakpoints (INT3 / 0xCC)
Memory Breakpoints (PAGE_GUARD)
Interrupt 0x2d
Interrupt 1
Trap Flag
Parent Process (Explorer.exe)
SeDebugPrivilege (Csrss.exe)
NtYieldExecution / SwitchToThread
TLS callbacks
Process jobs
Memory write watching
Page exception breakpoint detection
API hook detection (module bounds based)
Anti-Injection
Enumerate modules with EnumProcessModulesEx (32-bit, 64-bit, and all options)
Enumerate modules with ToolHelp32
Enumerate the process LDR structures with LdrEnumerateLoadedModules
Enumerate the process LDR structures directly
Walk memory with GetModuleInformation
Walk memory for hidden modules
Anti-Dumping
Erase PE header from memory
SizeOfImage
Timing-Angriffe [Anti-Sandbox]
RDTSC (with CPUID to force a VM Exit)
RDTSC (Locky version with GetProcessHeap & CloseHandle)
Sleep -> SleepEx -> NtDelayExecution
Sleep (in a loop a small delay)
Sleep and check if time was accelerated (GetTickCount)