
Analisi differenziale del malware in memoria
Uno strumento open source di analisi della memoria basato su Volatility. È pensato come un banco di prova per tecniche interessanti e innovative da mettere a disposizione della community. Queste tecniche tentano di accelerare il processo di investigazione attraverso la riduzione dei dati e la codifica di conoscenze esperte.
NOTE: Most DAMM output looks better piped through 'less -S' (upper 'S') as in:
python damm.py -h usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG] [--db DB] [--profile PROFILE] [--debug] [--info] [--tsv] [--grepable] [--filter FILTER] [--filtertype FILTERTYPE] [--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]
DAMM v1.0 Beta
optional arguments: -h, --help show this help message and exit -d DIR Path to additional plugin directory -p PLUGIN [PLUGIN ...] Plugin(s) to run. For a list of options use --info -f FILE Memory image file to run plugin on -k KDBG KDBG address for the images (in hex) --db DB SQLite db file, for efficient input/output --profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86) --debug Print debugging statements --info Print available volatility profiles, plugins --tsv Print screen formatted output. --grepable Print in grepable text format --filter FILTER Filter results on name:value pair, e.g., pid:42 --filtertype FILTERTYPE Filter match type; either "exact" or "partial", defaults to partial --diff BASELINE Diff the imageFile|db with this db file as a baseline -u FIELD [FIELD ...] Use the specified fields to determine uniqueness of memobjs when diffing --warnings Look for suspicious objects. -q Query the supplied db (via --db).
### Plugin supportati <a name="plugins"/>
Vedi #python damm.py --info
apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers
### Esempio <a name="example"/>
Fornisci un profilo come in Volatility, un'immagine di memoria e un elenco di plugin da eseguire (o 'all') per ottenere l'output del terminale:```
python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes | less -S
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes dlls modules)
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p all)
processes
offset name pid ppid prio image_path_name create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd command_line
0x25c8830 System 4 0 8 59 403 False True True True True False False False
0x225ada0 alg.exe 188 668 8 C:\WINDOWS\System32\alg.exe 2010-10-29 17:09:09 UTC+0000 6 0 107 False True True True True True True True C:\WINDOWS\System32\alg.exe
0x2114938 ipconfig.exe 304 968 8 2011-06-03 04:31:35 UTC+0000 2011-06-03 04:31:36 UTC+0000 0 0 False True True False True False False False
0x2086978 TSVNCache.exe 324 1196 8 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe 2010-10-29 17:11:49 UTC+0000 7 0 54 False True True True True True True True "C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
0x22df020 smss.exe 376 4 11 \SystemRoot\System32\smss.exe 2010-10-29 17:08:53 UTC+0000 3 19 False True True True True False False False \SystemRoot\System32\smss.exe
...
Per rendere persistenti questi risultati in un database SQLite, basta fornire un nome file per il database:``` python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes --db my_results.db
Questo stamperà i risultati sul terminale oltre a salvarli in 'my_results.db'
Per rivedere i risultati:```
python damm.py -p processes --db my_results.db
(Nota che non è più necessaria l'immagine di memoria né specificare un profilo: l'elenco verrà generato quasi istantaneamente, indipendentemente da quanto tempo ha richiesto l'elaborazione originale.)
Se in seguito desideri vedere i processi e altri plugin:``` python damm.py --profile WinXPSP2x86 -p processes dlls modules --db my_results.db
Farà:
1. consultare il db per l'output 'processes'
2. eseguire i plugin 'dlls' e 'modules'
3. mostrare i risultati
4. salvare i nuovi risultati nel db
Dopo aver salvato alcuni dati in un db, puoi interrogarlo con l'opzione -q```
python damm.py -q --db my_results.db
profile: WinXPSP2x86
memimg: WinXPSP2x86/stuxnet.vmem
COMPUTERNAME: JAN-DF663B3DBF1
plugins: processes dlls modules
I plugin hanno attributi che possono avere tipi per il filtraggio, ad es. per i processi: (usa --info per vedere tutti gli attributi dei plugin)``` offset name : string pid : pid ppid : pid image_path_name : string command_line : string create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd
Questi attributi e tipi possono essere sfruttati dalle funzioni di differenziazione e filtraggio di DAMM
### Differenziazione <a name="differencing"/>
Per utilizzare il motore di differenziazione, crea 2 database da 2 immagini di memoria distinte, ad esempio una prima e una dopo l'esecuzione di un malware```
python damm.py --profile WinXPSP2x86-f before.dmp -p processes --db before.db
python damm.py --profile WinXPSP2x86 -f after.dmp -p processes --db after.db
Quindi usa l'opzione --diff per il db di base (qui, il db dell'immagine di memoria non infetta).``` python damm.py -p processes --db after.db --diff before.db