
Detector experimental de patch de seção .text do Windows
======================
Experimental: comparação da seção .text do Windows - disco versus memória
Após ler sobre o malware Skeleton Key (http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/) desenvolver uma pequena ferramenta que compararia a seção .text de arquivos .exe e .dll no disco com seu equivalente na RAM para detectar patches.
Funcionando, no geral, para binários de 32 e 64 bits...
Esta ferramenta
C:\Data\NCC\!Code\Git.Public\WindowsPatchDetector\Debug>NCCGroupWindowsPatchDetector.exe -p 6104 -v
[*] Experimental Windows Patch Detector - https://github.com/olliencc/WindowsPatchDetector
[*] NCC Group Plc - http://www.nccgroup.com/
[*] -h for help
[i] + [Amazon Music Helper.exe - PID: 6104 in session 1 - window station Console]
[i] Module C:\Users\Ollie\AppData\Local\Amazon Music\Amazon Music Helper.exe .text section at virtual address 00941000 has 0 relocations
[i] Relocations at 00F15000 of 149092 bytes
[diff] Offset 0000000e (0000100e) of 4156286: 90 versus e8 diff a8
[diff] Offset 0000000f (0000100f) of 4156286: 90 versus 55 diff 3b
[diff] Offset 00000010 (00001010) of 4156286: 90 versus 94 diff fc
[diff] Offset 00000011 (00001011) of 4156286: 90 versus 02 diff 8e
[diff] Offset 00000012 (00001012) of 4156286: 90 versus 00 diff 90
[diff] Offset 00000013 (00001013) of 4156286: 90 versus 59 diff 37
[!] 6 bytes different from a total of 4156286 - relocs 0
... snip ...
[*] Experimental Windows Patch Detector - https://github.com/olliencc/WindowsPatchDetector
[*] NCC Group Plc - http://www.nccgroup.com/
[*] -h for help
[i] + [Amazon Music Helper.exe - PID: 6104 in session 1 - window station Console]
[i] Module C:\Users\Ollie\AppData\Local\Amazon Music\Amazon Music Helper.exe .text section at virtual address 00941000 has 0 relocations
[i] Relocations at 00F15000 of 149092 bytes
[!] 0 bytes different from a total of 4156286 - relocs 0
[i] Module C:\windows\SYSTEM32\ntdll.dll .text section at virtual address 778E1000 has 0 relocations
[i] Relocations at 77A42000 of 16956 bytes
[!] 0 bytes different from a total of 1005011 - relocs 0
[i] Module C:\windows\SYSTEM32\KERNEL32.DLL .text section at virtual address 75CA0000 has 0 relocations
[i] Relocations at 75DB0000 of 75024 bytes
[!] 0 bytes different from a total of 401365 - relocs 0
[i] Module C:\windows\SYSTEM32\KERNELBASE.dll .text section at virtual address 75DD1000 has 0 relocations
[i] Relocations at 75E9A000 of 23068 bytes
[!] 0 bytes different from a total of 771728 - relocs 0
[i] Module C:\windows\SYSTEM32\WS2_32.dll .text section at virtual address 75F01000 has 0 relocations
[i] Relocations at 75F4A000 of 9800 bytes
[!] 0 bytes different from a total of 215027 - relocs 0
[i] Module C:\windows\SYSTEM32\USER32.dll .text section at virtual address 754D1000 has 0 relocations
[i] Relocations at 75617000 of 17804 bytes
[diff] Offset 000002a4 (000012a4) of 508412: c0 versus a6 diff 1a
[diff] Offset 000002a5 (000012a5) of 508412: 8b versus 73 diff 18
[diff] Offset 000002a6 (000012a6) of 508412: 43 versus 00 diff 43
[diff] Offset 000002a7 (000012a7) of 508412: 02 versus 00 diff 02
[diff] Offset 000002a8 (000012a8) of 508412: d0 versus c1 diff 0f
[diff] Offset 000002a9 (000012a9) of 508412: 8b versus 73 diff 18
[diff] Offset 000002aa (000012aa) of 508412: 43 versus 00 diff 43
[diff] Offset 000002ab (000012ab) of 508412: 02 versus 00 diff 02
[diff] Offset 000002c0 (000012c0) of 508412: 00 versus dc diff 24
[diff] Offset 000002c1 (000012c1) of 508412: 8b versus 73 diff 18
[diff] Offset 000002c2 (000012c2) of 508412: 43 versus 00 diff 43
[diff] Offset 000002c3 (000012c3) of 508412: 02 versus 00 diff 02
[diff] Offset 000002c4 (000012c4) of 508412: 10 versus f7 diff 19
[diff] Offset 000002c5 (000012c5) of 508412: 8b versus 73 diff 18
[diff] Offset 000002c6 (000012c6) of 508412: 43 versus 00 diff 43
[diff] Offset 000002c7 (000012c7) of 508412: 02 versus 00 diff 02
[!] 16 bytes different from a total of 508412 - relocs 0
[i] Module C:\windows\SYSTEM32\SHELL32.dll .text section at virtual address 76201000 has 0 relocations
[i] Relocations at 77350000 of 421664 bytes
[!] 0 bytes different from a total of 7311956 - relocs 0
[i] Module C:\windows\SYSTEM32\ole32.dll .text section at virtual address 75321000 has 0 relocations
[i] Relocations at 75422000 of 40604 bytes
[!] 0 bytes different from a total of 930478 - relocs 0
[i] Module C:\windows\SYSTEM32\OLEAUT32.dll .text section at virtual address 77651000 has 0 relocations
[i] Relocations at 776DE000 of 25116 bytes
[!] 0 bytes different from a total of 545189 - relocs 0
[i] Module C:\windows\SYSTEM32\ADVAPI32.dll .text section at virtual address 75FF1000 has 0 relocations
[i] Relocations at 76063000 of 18220 bytes
[!] 0 bytes different from a total of 422057 - relocs 0
[i] Module C:\windows\SYSTEM32\WINMM.dll .text section at virtual address 742E1000 has 0 relocations
[i] Relocations at 742FE000 of 5772 bytes
[!] 0 bytes different from a total of 80266 - relocs 0
[i] Module C:\windows\SYSTEM32\CRYPT32.dll .text section at virtual address 76071000 has 0 relocations
[i] Relocations at 761EE000 of 37816 bytes
[!] 0 bytes different from a total of 905804 - relocs 0
[i] Module C:\windows\SYSTEM32\NSI.dll .text section at virtual address 75F51000 has 0 relocations
[i] Relocations at 75F56000 of 248 bytes
[!] 0 bytes different from a total of 6440 - relocs 0
[i] Module C:\windows\SYSTEM32\RPCRT4.dll .text section at virtual address 77761000 has 0 relocations
[i] Relocations at 7780B000 of 20048 bytes
[!] 0 bytes different from a total of 639180 - relocs 0
[i] Module C:\windows\SYSTEM32\GDI32.dll .text section at virtual address 773C1000 has 0 relocations
[i] Relocations at 774C2000 of 17348 bytes
[!] 0 bytes different from a total of 957247 - relocs 0
[i] Module C:\windows\SYSTEM32\msvcrt.dll .text section at virtual address 77591000 has 0 relocations
[i] Relocations at 7764A000 of 14360 bytes
[!] 0 bytes different from a total of 719071 - relocs 0
[i] Module C:\windows\SYSTEM32\combase.dll .text section at virtual address 75831000 has 0 relocations
[i] Relocations at 7596B000 of 76008 bytes
[!] 0 bytes different from a total of 1107156 - relocs 0
[i] Module C:\windows\SYSTEM32\SHLWAPI.dll .text section at virtual address 75B31000 has 0 relocations
[i] Relocations at 75B6E000 of 8744 bytes
[!] 0 bytes different from a total of 220948 - relocs 0
[i] Module C:\windows\SYSTEM32\sechost.dll .text section at virtual address 75621000 has 0 relocations
[i] Relocations at 7565C000 of 8064 bytes
[!] 0 bytes different from a total of 211508 - relocs 0
[i] Module C:\windows\SYSTEM32\WINMMBASE.dll .text section at virtual address 74081000 has 0 relocations
[i] Relocations at 7409E000 of 5636 bytes
[!] 0 bytes different from a total of 97074 - relocs 0
[i] Module C:\windows\SYSTEM32\MSASN1.dll .text section at virtual address 75FE1000 has 0 relocations
[i] Relocations at 75FED000 of 636 bytes
[!] 0 bytes different from a total of 35567 - relocs 0
[i] Module C:\windows\SYSTEM32\SspiCli.dll .text section at virtual address 752E1000 has 0 relocations
[i] Relocations at 752FB000 of 3796 bytes
[!] 0 bytes different from a total of 87463 - relocs 0
[i] Module C:\windows\SYSTEM32\cfgmgr32.dll .text section at virtual address 756A1000 has 0 relocations
[i] Relocations at 756D8000 of 7604 bytes