
idahunt ist ein Framework zur Analyse von Binärdateien mit IDA Pro und zur Suche nach Dingen in IDA Pro.

idahunt ist ein Framework zur Analyse von Binärdateien mit IDA Pro und zur Suche nach Dingen in IDA Pro. Es ist ein Kommandozeilenwerkzeug, um alle ausführbaren Dateien rekursiv aus einem bestimmten Ordner zu analysieren. Es führt IDA im Hintergrund aus, sodass Sie nicht jede Datei manuell öffnen müssen. Es unterstützt die Ausführung externer IDA-Python-Skripte.
Nützliche Beispiele sind (nicht abschließende Liste):
Die Möglichkeiten von IDA-Python-Skripten sind unbegrenzt. Sie können jedes vorhandene IDA-Python-Skript importieren oder eigene erstellen. Einige Beispiele:
idahunt.py: Hauptwerkzeug zur Analyse ausführbarer Dateienfilters/: enthält grundlegende Filter, die entscheiden, welche Dateien in einem Eingabeordner mit IDA analysiert werden sollen
filters/default.py: standardmäßiger Basisfilter, der nichts filtert und standardmäßig verwendet wirdfilters/ciscoasa.py: nützlich zur Analyse von Cisco-ASA-Firewall-Imagesfilters/hpilo.py: nützlich zur Analyse von HP-iLO-Imagesfilters/names.py: Basisfilter basierend auf Name, Namenslänge oder Erweiterungscript_template.py: enthält ein IDA-Python-Skript vom Typ hello worldC:\idahunt> C:\Python37-x64\python.exe .\idahunt.py -h
usage: idahunt.py [-h] [--inputdir INPUTDIR] [--analyse] [--open]
[--ida-args IDA_ARGS] [--scripts SCRIPTS [SCRIPTS ...]]
[--filter FILTER] [--cleanup] [--temp-cleanup] [--verbose]
[--max-ida MAX_IDA] [--list-only] [--version IDA_VERSION]
optional arguments:
-h, --help show this help message and exit
--inputdir INPUTDIR Input folder to search for files
--analyse, --analyze analyse all files i.e. create .idb for all of them
--open open all files into IDA (debug only)
--ida-args IDA_ARGS Additional arguments to pass to IDA (e.g.
-p<processor> -i<entry_point> -b<load_addr>)
--scripts SCRIPTS [SCRIPTS ...]
List of IDA Python scripts to execute in this order
--filter FILTER External python script with optional arguments
defining a filter for the names of the files to
analyse. See filters/names.py for example
--cleanup Cleanup i.e. remove .asm files that we don't need
--temp-cleanup Cleanup temporary database files i.e. remove .id0,
.id1, .id2, .nam, .dmp files if IDA Pro crashed and
did not delete them
--verbose be more verbose to debug script
--max-ida MAX_IDA Maximum number of instances of IDA to run at a time
(default: 10)
--list-only List only what files would be handled without
executing IDA
--version IDA_VERSION
Override IDA version (e.g. "7.5"). This is used to
find the path of IDA on Windows.
Sie können --list-only mit einer beliebigen Befehlszeile verwenden, um nur aufzulisten, was das Werkzeug tun würde, ohne es tatsächlich auszuführen.
C:\idahunt>idahunt.py --inputdir C:\re --analyse --filter "filters\names.py -a 32 -v" --list-only
[idahunt] Simulating only...
[idahunt] ANALYSING FILES
[idahunt] Analysing C:\re\cves\cve-2014-4076.dll
[idahunt] Analysing C:\re\cves\cve-2014-4076.exe
[idahunt] Analysing C:\re\DownloadExecute.exe
[idahunt] Analysing C:\re\ReverseShell.exe
Hier starten wir eine erste Analyse. Sie endet nach einigen Sekunden:
C:\idahunt>idahunt.py --inputdir C:\re --analyse --filter "filters\names.py -a 32 -v"
[idahunt] ANALYSING FILES
[idahunt] Analysing C:\re\cves\cve-2014-4076.dll
[idahunt] Analysing C:\re\cves\cve-2014-4076.exe
[idahunt] Analysing C:\re\DownloadExecute.exe
[idahunt] Analysing C:\re\ReverseShell.exe
[idahunt] Waiting on remaining 4 IDA instances
Hier bereinigen wir temporäre .asm-Dateien, die von der ersten Analyse erstellt wurden:
C:\idahunt>idahunt.py --inputdir C:\re --cleanup
[idahunt] Deleting C:\re\cves\cve-2014-4076.asm
[idahunt] Deleting C:\re\DownloadExecute.asm
[idahunt] Deleting C:\re\ReverseShell.asm
Wir können die erzeugten .idb- sowie einige .log-Dateien sehen, die das Ausgabefenster von IDA Pro enthalten.
C:\idahunt>tree /f C:\re
Folder PATH listing
Volume serial number is XXXX-XXXX
C:\RE
│ DownloadExecute.exe
│ DownloadExecute.idb
│ DownloadExecute.log
│ ReverseShell.exe
│ ReverseShell.idb
│ ReverseShell.log
│
└───cves
cve-2014-4076.dll
cve-2014-4076.exe
cve-2014-4076.idb
cve-2014-4076.log
Hier führen wir ein einfaches IDA-Python-Skript aus, das [script_template] I execute in IDA, yay! im Ausgabefenster von IDA Pro ausgibt.
C:\idahunt>idahunt.py --inputdir C:\re --filter "filters\names.py -a 32 -v" --scripts C:\idahunt\script_template.py
[idahunt] EXECUTE SCRIPTS
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\cves\cve-2014-4076.dll
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\cves\cve-2014-4076.exe
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\DownloadExecute.exe
[idahunt] Executing script C:\idahunt\script_template.py for C:\re\ReverseShell.exe
[idahunt] Waiting on remaining 4 IDA instances
Da es in der .log-Datei gespeichert ist, können wir überprüfen, dass es erfolgreich ausgeführt wurde: