
메모리 내 악성코드의 차등 분석
Volatility를 기반으로 구축된 오픈 소스 메모리 분석 도구입니다. 커뮤니티에 제공할 흥미로운 새로운 기술을 위한 실험장으로 의도되었습니다. 이러한 기술은 데이터 축소와 일부 전문 지식의 체계화를 통해 조사 과정을 가속화하려는 시도입니다.
NOTE: Most DAMM output looks better piped through 'less -S' (upper 'S') as in:
python damm.py -h usage: damm.py [-h] [-d DIR] [-p PLUGIN [PLUGIN ...]] [-f FILE] [-k KDBG] [--db DB] [--profile PROFILE] [--debug] [--info] [--tsv] [--grepable] [--filter FILTER] [--filtertype FILTERTYPE] [--diff BASELINE] [-u FIELD [FIELD ...]] [--warnings] [-q]
DAMM v1.0 Beta
optional arguments: -h, --help show this help message and exit -d DIR Path to additional plugin directory -p PLUGIN [PLUGIN ...] Plugin(s) to run. For a list of options use --info -f FILE Memory image file to run plugin on -k KDBG KDBG address for the images (in hex) --db DB SQLite db file, for efficient input/output --profile PROFILE Volatility profile for the images (e.g. WinXPSP2x86) --debug Print debugging statements --info Print available volatility profiles, plugins --tsv Print screen formatted output. --grepable Print in grepable text format --filter FILTER Filter results on name:value pair, e.g., pid:42 --filtertype FILTERTYPE Filter match type; either "exact" or "partial", defaults to partial --diff BASELINE Diff the imageFile|db with this db file as a baseline -u FIELD [FIELD ...] Use the specified fields to determine uniqueness of memobjs when diffing --warnings Look for suspicious objects. -q Query the supplied db (via --db).
### 지원 플러그인 <a name="plugins"/>
참조 #python damm.py --info
apihooks callbacks connections devicetree dlls evtlogs handles idt injections messagehooks mftentries modules mutants privileges processes services sids timers
### 예제 <a name="example"/>
Volatility에서처럼 프로필, 메모리 이미지, 실행할 플러그인 목록(또는 'all')을 제공하면 터미널 출력을 얻습니다:```
python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes | less -S
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes dlls modules)
(or python damm.py --profile WinXPSP2x86 -f memory.dmp -p all)
processes
offset name pid ppid prio image_path_name create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd command_line
0x25c8830 System 4 0 8 59 403 False True True True True False False False
0x225ada0 alg.exe 188 668 8 C:\WINDOWS\System32\alg.exe 2010-10-29 17:09:09 UTC+0000 6 0 107 False True True True True True True True C:\WINDOWS\System32\alg.exe
0x2114938 ipconfig.exe 304 968 8 2011-06-03 04:31:35 UTC+0000 2011-06-03 04:31:36 UTC+0000 0 0 False True True False True False False False
0x2086978 TSVNCache.exe 324 1196 8 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe 2010-10-29 17:11:49 UTC+0000 7 0 54 False True True True True True True True "C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
0x22df020 smss.exe 376 4 11 \SystemRoot\System32\smss.exe 2010-10-29 17:08:53 UTC+0000 3 19 False True True True True False False False \SystemRoot\System32\smss.exe
...
SQLite 데이터베이스에 이러한 결과를 영구 저장하려면 데이터베이스 파일 이름만 제공하면 됩니다:``` python damm.py --profile WinXPSP2x86 -f memory.dmp -p processes --db my_results.db
결과를 터미널에 출력하는 동시에 'my_results.db'에 저장합니다.
결과를 다시 보려면:```
python damm.py -p processes --db my_results.db
(참고: 더 이상 메모리 이미지나 프로필을 지정할 필요가 없으며, 원래 처리 시간이 얼마나 걸렸든 간에 목록이 거의 즉시 출력됩니다.)
나중에 프로세스 및 다른 플러그인을 보려면:``` python damm.py --profile WinXPSP2x86 -p processes dlls modules --db my_results.db
Will:
1. db에서 'processes' 출력을 조회한다
2. 'dlls' 및 'modules' 플러그인을 실행한다
3. 결과를 표시한다
4. 새로운 결과를 db에 저장한다
일단 db에 일부 데이터를 저장한 후에는 -q 스위치로 쿼리할 수 있다.```
python damm.py -q --db my_results.db
profile: WinXPSP2x86
memimg: WinXPSP2x86/stuxnet.vmem
COMPUTERNAME: JAN-DF663B3DBF1
plugins: processes dlls modules
Plugins have attributes that can have types for filtering, e.g., for processes: (use --info to see for all plugin attributes)``` offset name : string pid : pid ppid : pid image_path_name : string command_line : string create_time exit_time threads session_id handles is_wow64 pslist psscan thrdproc pspcid csrss session deskthrd
이러한 속성 및 유형은 DAMM의 차이점 및 필터링 기능에서 활용될 수 있습니다.
### 차이점 비교 <a name="differencing"/>
차이점 비교 엔진을 사용하려면, 맬웨어가 실행되기 전과 후의 이미지와 같이 서로 다른 두 메모리 이미지에서 2개의 데이터베이스를 생성하십시오.```
python damm.py --profile WinXPSP2x86-f before.dmp -p processes --db before.db
python damm.py --profile WinXPSP2x86 -f after.dmp -p processes --db after.db
그런 다음 기준 db(여기서는 감염되지 않은 메모리 이미지의 db)에 --diff 옵션을 사용하세요.``` python damm.py -p processes --db after.db --diff before.db