
メモリ内のマルウェアの差分分析
Volatilityの上に構築されたオープンソースのメモリ分析ツールです。コミュニティに提供するための興味深い新しい技術の試験場となることを目的としています。これらの技術は、データ削減と専門知識の形式化を通じて調査プロセスを高速化するための試みです。
NOTE: Most DAMM output looks better piped through 'less -S' (upper 'S') as in:
python damm.py -h usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG] [--db DB] [--profile PROFILE] [--debug] [--info] [--tsv] [--grepable] [--filter FILTER] [--filtertype FILTERTYPE] [--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]
DAMM v1.0 Beta
optional arguments: -h, --help show this help message and exit -d DIR Path to additional plugin directory -p PLUGIN [PLUGIN ...] Plugin(s) to run. For a list of options use --info -f FILE Memory image file to run plugin on -k KDBG KDBG address for the images (in hex) --db DB SQLite db file, for efficient input/output --profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86) --debug Print debugging statements --info Print available volatility profiles, plugins --tsv Print screen formatted output. --grepable Print in grepable text format --filter FILTER Filter results on name:value pair, e.g., pid:42 --filtertype FILTERTYPE Filter match type; either "exact" or "partial", defaults to partial --diff BASELINE Diff the imageFile|db with this db file as a baseline -u FIELD [FIELD ...] Use the specified fields to determine uniqueness of memobjs when diffing --warnings Look for suspicious objects. -q Query the supplied db (via --db).
### 対応プラグイン <a name="plugins"/>
参照 #python damm.py --info
apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers
### 例 <a name="example"/>
Volatility と同様に、プロファイル、メモリイメージ、実行するプラグインのリスト (または 'all') を指定すると、ターミナル出力が得られます:```
python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes | less -S
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes dlls modules)
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p all)
processes
offset name pid ppid prio image_path_name create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd command_line
0x25c8830 System 4 0 8 59 403 False True True True True False False False
0x225ada0 alg.exe 188 668 8 C:\WINDOWS\System32\alg.exe 2010-10-29 17:09:09 UTC+0000 6 0 107 False True True True True True True True C:\WINDOWS\System32\alg.exe
0x2114938 ipconfig.exe 304 968 8 2011-06-03 04:31:35 UTC+0000 2011-06-03 04:31:36 UTC+0000 0 0 False True True False True False False False
0x2086978 TSVNCache.exe 324 1196 8 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe 2010-10-29 17:11:49 UTC+0000 7 0 54 False True True True True True True True "C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
0x22df020 smss.exe 376 4 11 \SystemRoot\System32\smss.exe 2010-10-29 17:08:53 UTC+0000 3 19 False True True True True False False False \SystemRoot\System32\smss.exe
...
これらの結果をSQLiteデータベースに永続化させるには、データベースのファイル名を指定するだけです:``` python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes --db my_results.db
これにより、結果がターミナルに出力されるとともに、'my_results.db' に保存されます。
結果を再度表示するには:```
python damm.py -p processes --db my_results.db
(メモリイメージやプロファイルを指定する必要がなくなり、元の処理にどれだけ時間がかかったかに関係なく、リストはほぼ即座に表示されることに注意してください。)
後でプロセスやその他のプラグインを確認したい場合は:``` python damm.py --profile WinXPSP2x86 -p processes dlls modules --db my_results.db
実行内容:
1. db で 'processes' 出力を参照する
2. 'dlls' および 'modules' プラグインを実行する
3. 結果を表示する
4. 新しい結果を db に保存する
db にデータを保存したら、-q スイッチでクエリを実行できます。```
python damm.py -q --db my_results.db
profile: WinXPSP2x86
memimg: WinXPSP2x86/stuxnet.vmem
COMPUTERNAME: JAN-DF663B3DBF1
plugins: processes dlls modules
プラグインには、フィルタリング用の型を持つ属性があります。例: プロセス向け: (すべてのプラグイン属性を確認するには --info を使用してください)``` offset name : string pid : pid ppid : pid image_path_name : string command_line : string create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd
これらの属性とタイプは、DAMM の差分処理およびフィルタリング機能によって活用できます。
### 差分 <a name="differencing"/>
差分エンジンを使用するには、たとえばマルウェアの実行前と実行後の 2 つの異なるメモリイメージから、2 つのデータベースを作成します。```
python damm.py --profile WinXPSP2x86-f before.dmp -p processes --db before.db
python damm.py --profile WinXPSP2x86 -f after.dmp -p processes --db after.db
次に、ベースラインのDB(ここでは、感染していないメモリイメージからのDB)に対して --diff オプションを使用します。```
python damm.py -p processes --db after.db --diff before.db