· 8 years ago · Feb 22, 2018, 04:02 AM
1The Art of Memory Forensics
2----------------------------------------------------------------------
3Chapter 1: Systems Overview
4----------------------------------------------------------------------
5
61. What component assists the CPU in address translation?
7
8 A) The Memory Management Unit (MMU)
9 B) The Address Translation Unit (ATU)
10 C) The Central Memory Hub (CMH)
11 D) The Memory Management Controller (MMC)
12
13The correct answer is: A
14
152. When dealing with raw, padded memory dumps, a physical address is an offset into the memory dump file.
16
17 True or False?
18
19The correct answer is: True
20
213. Which statement(s) are false?
22
23 A) IA32 architecture is also known as x86
24 B) Physical Address Extension (PAE) allows up to 64GB of physical memory
25 C) 64-bit CPUs only actually use 52 bits of the available address space
26 D) A typical page size is 4KB, but it can be larger if the page size entry (PSE) flag is set
27 E) All of the above
28
29The correct answer is: C (they use 48 bits)
30
314. Which CPU register is used to store the directory table base (page directory base)?
32
33 A) CR0
34 B) EAX
35 C) CR3
36 D) DR3
37
38The correct answer is: C
39
405. Which statement(s) are true?
41
42 A) Paging allows processes to "see" more RAM than is physically present
43 B) The page fault handler code must never be paged
44 C) Paging complicates memory forensics because not all data is memory resident at the time of acquisition
45 D) Paging writes potentially valuable volatile evidence to non-volatile storage such as disk
46 E) All of the above
47
48The correct answer is: E
49
506. The winlogon.exe process (PID 628) in sample001.bin has a virtual address 0x77a80000 and DTB value 0x682e000. What is the corresponding physical offset? What do you see at the physical offset within the file?
51
52The correct answer is: 72159232 (an MZ header)
53
54$ python vol.py -f AMF_MemorySamples/windows/sample001.bin volshell
55Volatility Foundation Volatility Framework 2.4 (Beta)
56Current context: System @ 0x823c8830, pid=4, ppid=0 DTB=0x39000
57Python 2.7.6 (v2.7.6:3a1db0d2747e, Nov 10 2013, 00:42:54)
58Type "copyright", "credits" or "license" for more information.
59
60IPython 2.0.0 -- An enhanced Interactive Python.
61? -> Introduction and overview of IPython's features.
62%quickref -> Quick reference.
63help -> Python's own help system.
64object? -> Details about 'object', use 'object??' for extra details.
65
66In [1]: cc(pid = 628)
67Current context: winlogon.exe @ 0x82189da0, pid=628, ppid=356 DTB=0x682e000
68
69In [2]: proc().get_process_address_space().vtop(0x77a80000)
70Out[2]: 72159232
71
72In [3]: quit()
73
74$ xxd -s 72159232 AMF_MemorySamples/windows/sample001.bin | less
75
7644d1000: 4d5a 9000 0300 0000 0400 0000 ffff 0000 MZ..............
7744d1010: b800 0000 0000 0000 4000 0000 0000 0000 ........@.......
7844d1020: 0000 0000 0000 0000 0000 0000 0000 0000 ................
7944d1030: 0000 0000 0000 0000 0000 0000 f000 0000 ................
8044d1040: 0e1f ba0e 00b4 09cd 21b8 014c cd21 5468 ........!..L.!Th
8144d1050: 6973 2070 726f 6772 616d 2063 616e 6e6f is program canno
8244d1060: 7420 6265 2072 756e 2069 6e20 444f 5320 t be run in DOS
8344d1070: 6d6f 6465 2e0d 0d0a 2400 0000 0000 0000 mode....$.......
8444d1080: 1ac1 36e1 5ea0 58b2 5ea0 58b2 5ea0 58b2 ..6.^.X.^.X.^.X.
85
86----------------------------------------------------------------------
87Chapter 2: Data Structures
88----------------------------------------------------------------------
89
901. Which of the following data types consume 4 bytes on a 32-bit system?
91
92 A) char
93 B) unsigned int
94 C) long
95 D) pointer to an int
96 E) pointer to a char
97
98The correct answer is: B, C, D, E
99
1002. Which statement(s) are false about arrays?
101
102 A) Elements can be found by multiplying the desired index by the size of an element and adding it to the array's base address
103 B) Elements are contiguous in memory
104 C) Elements must be of a single data type (homogenous)
105 D) Arrays cannot store pointers
106
107The correct answer is: D
108
1093. Which statements(s) are true about structures?
110
111 A) Structures can store various different data types
112 B) Structure sizes and member offsets can vary depending on compiler optimizations
113 C) Operating systems and applications make heavy use of structures
114 D) The names of structure members should indicate their purpose
115
116The correct answer is: A, B, C, D
117
1184. Linked lists are easily manipulated by rootkits.
119
120 True or False?
121
122The correct answer is: True
123
1245. Performing memory forensics at the physical layer (i.e. without virtual address translation) limits analysis because:
125
126 A) Strings that cross page boundaries may be fragmented in physical memory
127 B) You cannot traverse linked lists
128 C) Some hash tables and trees are never found in physical memory
129 D) _UNICODE_STRING data types store metadata separately from the actual string content
130
131The correct answer is: A, B, D
132
1336. Perform the following steps:
134
135 A) Create a C source file with one or more data structures
136 B) Initialize the structure members in the your main() function and print out their values
137 C) Compile it with GCC or Microsoft Visual Studio Express
138 D) Analyze the binary in a disassembler, or pause it in a debugger, and inspect the offsets for the structure members being passed to the print function
139 E) Do your offsets match your expectations?
140
141The correct answer is: N/A
142
143----------------------------------------------------------------------
144Chapter 3: The Volatility Framework
145----------------------------------------------------------------------
146
1471. Install Volatility and the dependency libraries (unless you're working with the standalone version).
148
149The correct answer is: N/A
150
1512. Run the "vol.py --info" command. What profiles does your version support?
152
153The correct answer is: N/A
154
1553. Run the "vol.py --help" command with and without a plugin name. How does the output differ?
156
157The correct answer is: You'll see the plugin-specific options
158
1594. Run the kdbgscan plugin against a Windows memory sample.
160
161 A) What profile does it suggest?
162 B) What is the virtual address of the kernel debugger data structure?
163 C) Were any inaccurate profiles suggested? Why or why not?
164
165The virtual address will be shown on the line with "Offset(V)"
166In some cases, you'll see slightly inaccurate profiles (for example Win7 SP1 versus Win7 SP0) because the OS data structures look similar. In these cases, look at the Service Pack value in the kdbgscan output to determine which suggestion is correct.
167
1685. Using the profile you determined in step 4, list processes in your memory dump. Then run the same plugin again, but redirect output to a text file so you can save it for later analysis.
169
170The correct answer is: N/A
171
1726. Perform the following steps:
173
174 A) Copy exampleplugin.py into volatility/plugins
175 B) Edit exampleplugin.py and change the name from ExamplePlugin to a name of your choice
176 C) Edit the description of the plugin
177 D) Edit the plugin to print the process ID (UniqueProcessId) in addition to the process name
178 E) Run "vol.py --info" and see if your new plugin is registered
179 F) Run your new plugin and observe the output
180 G) Add a new method named render_csv (comma separated values) to the plugin and configure it to output data in CSV format
181 H) Run the plugin with --output=csv and observe the output
182
183The correct answer is: (see below for an example)
184
185import volatility.utils as utils
186import volatility.commands as commands
187import volatility.win32.tasks as tasks
188
189class MyNewPlugin(commands.Command):
190 """This is an example plugin that I modified"""
191
192 def calculate(self):
193 """This method performs the work"""
194
195 addr_space = utils.load_as(self._config)
196 for proc in tasks.pslist(addr_space):
197 yield proc
198
199 def render_text(self, outfd, data):
200 """This method formats output to the terminal.
201 :param outfd | <file>
202 data | <generator>
203 """
204
205 for proc in data:
206 outfd.write("Process: {0} PID {1}\n".format(proc.ImageFileName, proc.UniqueProcessId))
207
208 def render_csv(self, outfd, data):
209 for proc in data:
210 outfd.write("{0},{1}\n".format(proc.ImageFileName, proc.UniqueProcessId))
211
212----------------------------------------------------------------------
213Chapter 4: Memory Acquisition
214----------------------------------------------------------------------
215
2161. If a suspect computer is not powered on, you can attempt to recover memory in which of the following ways?
217
218 A) page files on disk
219 B) hibernation files
220 C) old crash dumps
221 D) introspection
222
223The correct answer is: A, B, C
224
2252. Why is memory acquisition not a trivial task? What are some of the "gotchas" you need to watch out for?
226
227The correct answer is: cache coherency, device memory, anti-forensics, etc.
228
2293. Which API is not commonly used by acquisition tools?
230
231 A) MmCreateMemoryDump
232 B) MmMapMemoryDumpMdl
233 C) MmProbeAndLockPages
234 D) ZwMapViewOfMemory
235 E) MmMapIoSpace
236
237The correct answer is: A
238
2394. It is important to run live response tools to gather evidence before acquiring physical memory, so that your memory capture contains the extra data generated by the live IR tools.
240
241 True or False?
242
243The correct answer is: False (you should run live IR tools *after* acquiring physical memory, so you don't taint the evidence)
244
2455. Perform the following steps:
246
247 A) Dump memory from one of your machines to local USB/Firewire/ESATA
248 B) Dump memory across the network (you can use a NAT or Host-only VM configuration). Make sure to use compression and encryption
249 C) If possible, analyze memory using remote interrogation. Capture traffic while you run Volatility plugins. How much data is transferred with a basic process listing?
250
251The correct answer is: N/A
252
2536. Perform the following steps:
254
255 A) Analyze the registry of a target system to determine how many page files are in use
256 B) Extract the page files from the running system (with TSK Windows binaries).
257 C) Can Volatility analyze page files directly? Why or why not?
258 D) Can you use Volatility's imagecopy plugin to convert a page file into a raw memory dump? Why or why not?
259 E) Use page_brute to scan across your extracted page files. Does it find any hits?
260 F) If necessary, extend page_brute's default Yara rules and scan your page files again.
261
262The correct answer is: Volatility cannot analyze page files directly at this time. You cannot use imagecopy to convert a page file into a raw memory dump (page file is just the "holes").
263
264----------------------------------------------------------------------
265Chapter 5: Windows Objects and Pool Allocation
266----------------------------------------------------------------------
267
2681. Run the objtypescan plugin against a memory dump from a system you own.
269
270 A) How many different executive object types exist?
271 B) Does the list of objects match what WinObj (Sysinternals) reports?
272 C) What's the most highly used object type on your system?
273 D) Which object types can be paged to disk?
274 E) What is the 4-byte key (AKA tag) for process objects?
275
276The correct answer is: The number of executive object types differ per OS version, and the most highly used object type will differ per system. Here's an example:
277
278$ python ~/Desktop/GitHub/volatility/vol.py -f Win81x64-bf5ed93b.vmem --profile=Win8SP1x64 objtypescan
279Volatility Foundation Volatility Framework 2.4 (Beta)
280Offset nObjects nHandles Key Name PoolType
281------------------ ------------------ ------------------ -------- ------------------------------ --------------------
2820x000000007cd65080 0x19 0x14 Dxgk DxgkSharedResource PagedPool
2830x000000007cd65220 0x1 0x1 Dxgk DxgkSharedSyncObject PagedPool
2840x000000007d00e890 0x5 0x5 Filt FilterCommunicationPort NonPagedPoolNx
2850x000000007d04d4d0 0xf 0xf PcwO PcwObject PagedPool
2860x000000007e465cf0 0x5 0x5 Filt FilterConnectionPort NonPagedPoolNx
2870x000000007e4725f0 0x3e 0x197 Proc Process NonPagedPoolNx
2880x000000007e472d70 0x0 0x0 Debu DebugObject NonPagedPoolNx
2890x000000007e473420 0x0 0x0 User UserApcReserve NonPagedPoolNx
2900x000000007e474610 0x18 0x0 Call Callback NonPagedPoolNx
2910x000000007e475080 0x31 0xa0 Dire Directory PagedPool
2920x000000007e476ce0 0x60d 0x1e5 Toke Token PagedPool
2930x000000007e481740 0x1ace 0x1b9b Even Event NonPagedPoolNx
2940x000000007e481c60 0x3 0x0 TmTx TmTx NonPagedPoolNx
2950x000000007e481dc0 0x8 0x8 TmTm TmTm NonPagedPoolNx
2960x000000007e481f20 0x1ca6 0x552 File File NonPagedPoolNx
2970x000000007e4823f0 0x530 0x530 Wait WaitCompletionPacket NonPagedPoolNx
2980x000000007e482550 0xc0 0xb6 IoCo IoCompletion NonPagedPoolNx
2990x000000007e4826b0 0x7e 0x0 Driv Driver NonPagedPoolNx
3000x000000007e485f20 0x2e 0x0 ObjT Type NonPagedPoolNx
3010x000000007e487c50 0x0 0x0 Prof Profile NonPagedPoolNx
3020x000000007e487db0 0x14d 0x14d IRTi IRTimer NonPagedPoolNx
3030x000000007e48a590 0x0 0x0 IoCo IoCompletionReserve NonPagedPoolNx
3040x000000007e48cc10 0x6 0x6d Wind WindowStation NonPagedPoolNx
3050x000000007e48cd70 0x1 0x0 Keye KeyedEvent PagedPool
3060x000000007e48d470 0x1c5 0x0 Devi Device NonPagedPoolNx
3070x000000007e48d5d0 0x1 0x0 Cont Controller NonPagedPoolNx
3080x000000007e48d730 0xb 0x0 Adap Adapter NonPagedPoolNx
3090x000000007e48f830 0xa6 0xa6 TpWo TpWorkerFactory NonPagedPoolNx
3100x000000007e48f990 0x25 0x29 Comp Composition NonPagedPoolNx
3110x000000007e48faf0 0xa 0x3f Desk Desktop NonPagedPoolNx
3120x000000007e490980 0x0 0x0 TmEn TmEn NonPagedPoolNx
3130x000000007e490ae0 0x11 0x11 TmRm TmRm NonPagedPoolNx
3140x000000007e492470 0x377 0x444 Thre Thread NonPagedPoolNx
3150x000000007e497660 0xd0 0x5f Symb SymbolicLink PagedPool
3160x000000007e497bb0 0x16 0x1b Job Job NonPagedPoolNx
3170x000000007e4aceb0 0x191 0x228 Muta Mutant NonPagedPoolNx
3180x000000007e544730 0x4a0 0x49a ALPC ALPC Port NonPagedPoolNx
3190x000000007e546790 0x8c5 0x8d5 Key Key PagedPool
3200x000000007e549080 0x705 0x325 Sect Section PagedPool
3210x000000007e549730 0x2 0x10 Sess Session NonPagedPoolNx
3220x000000007e54b8c0 0x5f 0x5f Time Timer NonPagedPoolNx
3230x000000007e54ba20 0x559 0x564 Sema Semaphore NonPagedPoolNx
3240x000000007e5512c0 0x5 0x2 Powe PowerRequest NonPagedPoolNx
3250x000000007e552a30 0x14 0x13 WmiG WmiGuid NonPagedPoolNx
3260x000000007e559a30 0x7 0x7 EtwC EtwConsumer NonPagedPoolNx
3270x000000007e55aa30 0xf66 0xf66 EtwR EtwRegistration NonPagedPoolNx
328
329The list of objects shown by objtypescan should match WinObj. In the example output above, the most frequently used object type is File (file objects).
330
331Objects in the PagedPool can be paged. The tag/key for process objects is Proc.
332
3332. Perform the following steps:
334
335 A) Take two memory dumps - one before running allocator.exe and one after
336 B) Use the pooltracker plugin to compare the changes it makes to the "Muta" pools
337 C) If you integrate pooltag.txt into your pooltracker plugin output, what description does it provide for "Muta" objects?
338 D) Run the mutantscan plugin. Does the output support the theories about allocator.exe's activity based on pool tag use statistics?
339
340Here's an example of the before and after status:
341
342$ python vol.py before.vmem --profile=Win7SP1x86 pooltracker -t Muta
343Volatility Foundation Volatility Framework 2.4 (Beta)
344Tag NpAllocs NpFrees NpBytes PgAllocs PgFrees PgBytes Driver Reason
345------ -------- -------- -------- -------- -------- -------- -------------------- ------
346Muta 655173 646431 908624 0 0 0
347
348$ python vol.py after.vmem --profile=Win7SP1x86 pooltracker -t Muta
349Volatility Foundation Volatility Framework 2.4 (Beta)
350Tag NpAllocs NpFrees NpBytes PgAllocs PgFrees PgBytes Driver Reason
351------ -------- -------- -------- -------- -------- -------- -------------------- ------
352Muta 660764 646652 1424032 0 0 0
353
354As you can see, there are approximately 5591 new mutex objects allocated. By integrating the pooltag.txt file, you'll see these objects are "Mutant objects":
355
356$ python vol.py after.vmem --profile=Win7SP1x86 pooltracker -t Muta --tagfile=~/Desktop/pooltag.txt
357Volatility Foundation Volatility Framework 2.4 (Beta)
358Tag NpAllocs NpFrees NpBytes PgAllocs PgFrees PgBytes Driver Reason
359------ -------- -------- -------- -------- -------- -------- -------------------- ------
360Muta 660764 646652 1424032 0 0 0 <unknown> Mutant objects
361
362When running the mutantscan plugin, you'll see the new mutexes:
363
364$ python vol.py after.vmem --profile=Win7SP1x86 mutantscan
365Volatility Foundation Volatility Framework 2.4 (Beta)
366Offset(P) #Ptr #Hnd Signal Thread CID Name
367------------------ -------- -------- ------ ---------- --------- ----
3680x0000000000184b70 2 1 0 0x864ed290 3820:824 Mutex6145
3690x0000000000184bd0 2 1 0 0x864ed290 3820:824 Mutex6144
3700x0000000000184c30 2 1 0 0x864ed290 3820:824 Mutex6143
3710x0000000000935040 2 1 0 0x864ed290 3820:824 Mutex2976
3720x00000000009350d8 2 1 0 0x864ed290 3820:824 Mutex2977
3730x0000000000935cf8 2 1 0 0x864ed290 3820:824 Mutex7138
3740x0000000000935d58 2 1 0 0x864ed290 3820:824 Mutex7137
3750x0000000000935db8 2 1 0 0x864ed290 3820:824 Mutex7136
3760x00000000009585b0 2 1 0 0x864ed290 3820:824 Mutex471
3770x0000000000958808 2 1 0 0x864ed290 3820:824 Mutex3189
3780x0000000000958868 2 1 0 0x864ed290 3820:824 Mutex3188
3790x00000000009589b0 2 1 0 0x864ed290 3820:824 Mutex404
3800x0000000000cee450 2 1 0 0x864ed290 3820:824 Mutex9685
3810x0000000000cee4b0 2 1 0 0x864ed290 3820:824 Mutex9684
3820x0000000000cee510 2 1 0 0x864ed290 3820:824 Mutex9683
3830x0000000000cee570 2 1 0 0x864ed290 3820:824 Mutex9682
3840x0000000000cee670 2 1 0 0x864ed290 3820:824 Mutex2693
3850x0000000000cee6d0 2 1 0 0x864ed290 3820:824 Mutex2692
3860x0000000000cee7c8 2 1 0 0x864ed290 3820:824 Mutex8029
3870x0000000000cee828 2 1 0 0x864ed290 3820:824 Mutex8028
3880x0000000000cee888 2 1 0 0x864ed290 3820:824 Mutex8027
3890x0000000000cee8e8 2 1 0 0x864ed290 3820:824 Mutex8026
390[snip]
391
3923. The memory image sample002.bin is running a kernel driver that defines the following structure type. The driver allocates structures from nonpaged pools using tag 'RdeR'. Write a pool scanner to find these allocations and parse them.
393
394 typedef struct _MMREDIR {
395 int src_port;
396 int dst_port;
397 int redirect_port;
398 char src_address[32];
399 char dst_address[32];
400 char redirect_address[32];
401 } MMREDIR, *PMMREDIR;
402
403Here's an example plugin:
404
405import volatility.plugins.common as common
406import volatility.utils as utils
407import volatility.poolscan as poolscan
408import volatility.obj as obj
409
410class RedirScanner(poolscan.SinglePoolScanner):
411 checks = [
412 ('PoolTagCheck', dict(tag = 'RdeR')),
413 ('CheckPoolType', dict(non_paged = True, paged = False)),
414 ('CheckPoolSize', dict(condition = lambda x: x == 120)),
415 ]
416
417class RedirTypes(obj.ProfileModification):
418
419 def modification(self, profile):
420 profile.vtypes.update({
421 '_MMREDIR': [ None, {
422 'src_port': [ 0, ['int']],
423 'dst_port': [ 4, ['int']],
424 'redirect_port': [ 8, ['int']],
425 'src_address': [ 12, ['String', dict(length = 32)]],
426 'dst_address': [ 44, ['String', dict(length = 32)]],
427 'redirect_address': [ 76, ['String', dict(length = 32)]],
428 }]})
429
430class RedirScan(common.AbstractWindowsCommand):
431 """Scan for _MMREDIR structures allocated by RedirPro"""
432
433 def calculate(self):
434
435 ## Get a kernel address space
436 kernel_space = utils.load_as(self._config)
437 header_size = kernel_space.profile.get_obj_size("_POOL_HEADER")
438
439 for offset in RedirScanner().scan(kernel_space):
440
441 mmredir = obj.Object("_MMREDIR",
442 offset = offset + header_size,
443 vm = kernel_space)
444
445 yield mmredir
446
447 def render_text(self, outfd, data):
448
449 self.table_header(outfd, [("Offset", "[addrpad]"),
450 ("SrcPort", "8"),
451 ("DstPort", "8"),
452 ("RedirPort", "8"),
453 ("SrcAddr", "20"),
454 ("DstAddr", "20"),
455 ("RedirAddr", "20"),
456 ])
457 for mmredir in data:
458 self.table_row(outfd,
459 mmredir.obj_offset,
460 mmredir.src_port,
461 mmredir.dst_port,
462 mmredir.redirect_port,
463 mmredir.src_address,
464 mmredir.dst_address,
465 mmredir.redirect_address)
466
467The plugin's output should appear like this:
468
469$ python vol.py -f sample002.bin redirscan --profile=Win7SP1x86
470Volatility Foundation Volatility Framework 2.4 (Beta)
471Offset SrcPort DstPort RedirPort SrcAddr DstAddr RedirAddr
472---------- -------- -------- --------- -------------------- -------------------- --------------------
4730x85f336e8 0 80 8080 24.194.35.12 66.214.40.105 10.10.3.20
4740x861f3008 0 0 0
4750x86379200 0 0 0
4760x863a2120 30021 443 22 any 66.214.40.105 192.168.172.42
4770x864251f8 0 0 0
478
4794. Run the pslist and psscan plugins against sample003.bin.
480
481 A) Which process(es) are active?
482 B) Which process(es) have terminated?
483 C) Which process(es) are leftover from a previous reboot?
484
485All processes in the pslist output are active:
486
487$ python vol.py -f sample003.bin pslist
488Volatility Foundation Volatility Framework 2.4 (Beta)
489Offset(V) Name PID PPID Thds Hnds Sess Wow64 Start Exit
490---------- -------------------- ------ ------ ------ -------- ------ ------ ------------------------------ ------------------------------
4910x819cc830 System 4 0 51 254 ------ 0
4920x817e4670 smss.exe 360 4 3 19 ------ 0 2008-11-26 07:38:11 UTC+0000
4930x8181bd78 csrss.exe 596 360 10 322 0 0 2008-11-26 07:38:13 UTC+0000
4940x8182b100 winlogon.exe 620 360 16 503 0 0 2008-11-26 07:38:14 UTC+0000
4950x8183ba78 services.exe 672 620 15 245 0 0 2008-11-26 07:38:15 UTC+0000
4960x817dbc30 lsass.exe 684 620 21 347 0 0 2008-11-26 07:38:15 UTC+0000
4970x81859d70 svchost.exe 844 672 19 198 0 0 2008-11-26 07:38:18 UTC+0000
4980x8183d360 svchost.exe 932 672 10 229 0 0 2008-11-26 07:38:18 UTC+0000
4990x818a2300 svchost.exe 1064 672 63 1308 0 0 2008-11-26 07:38:20 UTC+0000
5000x817f7da0 svchost.exe 1164 672 5 77 0 0 2008-11-26 07:38:23 UTC+0000
5010x8180e6f0 svchost.exe 1264 672 14 209 0 0 2008-11-26 07:38:25 UTC+0000
5020x817ca478 explorer.exe 1516 1452 12 362 0 0 2008-11-26 07:38:27 UTC+0000
5030x816e75e8 spoolsv.exe 1648 672 12 112 0 0 2008-11-26 07:38:28 UTC+0000
5040x816af860 VMwareTray.exe 1896 1516 1 26 0 0 2008-11-26 07:38:31 UTC+0000
5050x816af448 VMwareUser.exe 1904 1516 1 28 0 0 2008-11-26 07:38:31 UTC+0000
5060x816a13c0 VMwareService.e 1756 672 3 45 0 0 2008-11-26 07:38:45 UTC+0000
5070x816557e0 alg.exe 512 672 6 105 0 0 2008-11-26 07:38:53 UTC+0000
5080x81643b28 wuauclt.exe 1372 1064 8 225 0 0 2008-11-26 07:39:38 UTC+0000
5090x8164e3a8 wscntfy.exe 560 1064 1 31 0 0 2008-11-26 07:44:57 UTC+0000
510
511According to the psscan output, only one process is terminated (cmd.exe pid 940)
512
513$ python vol.py -f sample003.bin psscan
514Volatility Foundation Volatility Framework 2.4 (Beta)
515Offset(P) Name PID PPID PDB Time created Time exited
516------------------ ---------------- ------ ------ ---------- ------------------------------ ------------------------------
5170x000000000181b748 alg.exe 992 660 0x08140260 2008-11-15 23:43:25 UTC+0000
5180x0000000001843b28 wuauclt.exe 1372 1064 0x08140180 2008-11-26 07:39:38 UTC+0000
5190x000000000184e3a8 wscntfy.exe 560 1064 0x081402a0 2008-11-26 07:44:57 UTC+0000
5200x00000000018557e0 alg.exe 512 672 0x08140260 2008-11-26 07:38:53 UTC+0000
5210x000000000185dda0 cmd.exe 940 1516 0x081401a0 2008-11-26 07:43:39 UTC+0000 2008-11-26 07:45:49 UTC+0000
5220x00000000018a13c0 VMwareService.e 1756 672 0x08140220 2008-11-26 07:38:45 UTC+0000
5230x00000000018af448 VMwareUser.exe 1904 1516 0x08140100 2008-11-26 07:38:31 UTC+0000
5240x00000000018af860 VMwareTray.exe 1896 1516 0x08140200 2008-11-26 07:38:31 UTC+0000
5250x00000000018e75e8 spoolsv.exe 1648 672 0x081401e0 2008-11-26 07:38:28 UTC+0000
5260x00000000019456e8 csrss.exe 592 360 0x08140040 2008-11-15 23:42:56 UTC+0000
5270x0000000001946020 svchost.exe 828 660 0x081400c0 2008-11-15 23:42:57 UTC+0000
5280x00000000019467e0 services.exe 660 616 0x08140080 2008-11-15 23:42:56 UTC+0000
5290x000000000194f658 svchost.exe 1016 660 0x08140100 2008-11-15 23:42:57 UTC+0000
5300x00000000019533c8 svchost.exe 924 660 0x081400e0 2008-11-15 23:42:57 UTC+0000
5310x00000000019ca478 explorer.exe 1516 1452 0x081401c0 2008-11-26 07:38:27 UTC+0000
5320x00000000019dbc30 lsass.exe 684 620 0x081400a0 2008-11-26 07:38:15 UTC+0000
5330x00000000019e4670 smss.exe 360 4 0x08140020 2008-11-26 07:38:11 UTC+0000
5340x00000000019f7da0 svchost.exe 1164 672 0x08140140 2008-11-26 07:38:23 UTC+0000
5350x0000000001a0e6f0 svchost.exe 1264 672 0x08140160 2008-11-26 07:38:25 UTC+0000
5360x0000000001a1bd78 csrss.exe 596 360 0x08140040 2008-11-26 07:38:13 UTC+0000
5370x0000000001a2b100 winlogon.exe 620 360 0x08140060 2008-11-26 07:38:14 UTC+0000
5380x0000000001a3ba78 services.exe 672 620 0x08140080 2008-11-26 07:38:15 UTC+0000
5390x0000000001a3d360 svchost.exe 932 672 0x081400e0 2008-11-26 07:38:18 UTC+0000
5400x0000000001a59d70 svchost.exe 844 672 0x081400c0 2008-11-26 07:38:18 UTC+0000
5410x0000000001aa2300 svchost.exe 1064 672 0x08140120 2008-11-26 07:38:20 UTC+0000
5420x0000000001bcc830 System 4 0 0x00319000
543
544All of the processes that started on 2008-11-15 are leftover from a previous reboot.
545
5465. Which of the following is not a weakness of the pool tag scanning approach?
547
548 A) It's possible to find false positives (decoys, fake objects, etc.)
549 B) Pool tags can be manipulated because they're not essential to the OS
550 C) Large allocations (> 4096 bytes) cannot be found with pool tag scanning
551 D) Not all kernel allocations are tagged in the first place (i.e. ExAllocatePool)
552 E) All of the above
553
554The correct answer is: E
555
556----------------------------------------------------------------------
557Chapter 6: Processes, Handles, and Tokens
558----------------------------------------------------------------------
559
5601. Which of the following situations should have you worried?
561
562 A) Two or more instances of svchost.exe are running
563 B) The parent of winlogon.exe is services.exe
564 C) csrss.exe is running from the "C:\Windows\system32" directory
565 D) ssms.exe is running
566 E) explorer.exe is running from the "C:\Windows\system32" directory
567
568The correct answer is: B, D, E
569
5702. Run the psscan plugin on one of your memory images and generate a Graphviz diagram (--output=dot --output-file=graph.dot). Why doesn't explorer.exe have a parent?
571
572The correct answer is: Explorer's parent (userinit.exe) typically exits after starting explorer.
573
5743. Run the psxview plugin against sample003.bin.
575
576 A) Which process(es) are hidden?
577 B) In what ways did the rootkit attempt to hide?
578
579$ python vol.py -f sample003.bin psxview --apply-rules
580Volatility Foundation Volatility Framework 2.4 (Beta)
581Offset(P) Name PID pslist psscan thrdproc pspcid csrss session deskthrd ExitTime
582---------- -------------------- ------ ------ ------ -------- ------ ----- ------- -------- --------
5830x01a2b100 winlogon.exe 620 True True True True True True True
5840x01a3d360 svchost.exe 932 True True True True True True True
5850x018a13c0 VMwareService.e 1756 True True True True True True True
5860x018e75e8 spoolsv.exe 1648 True True True True True True True
5870x019dbc30 lsass.exe 684 True True True True True True True
5880x0184e3a8 wscntfy.exe 560 True True True True True True True
5890x018af860 VMwareTray.exe 1896 True True True True True True True
5900x01a4bc20 network_listene 1696 False False True True True True True
5910x01843b28 wuauclt.exe 1372 True True True True True True True
5920x01a59d70 svchost.exe 844 True True True True True True True
5930x018af448 VMwareUser.exe 1904 True True True True True True True
5940x019f7da0 svchost.exe 1164 True True True True True True True
5950x018557e0 alg.exe 512 True True True True True True True
5960x01a3ba78 services.exe 672 True True True True True True True
5970x019ca478 explorer.exe 1516 True True True True True True True
5980x01a0e6f0 svchost.exe 1264 True True True True True True True
5990x01aa2300 svchost.exe 1064 True True True True True True True
6000x019e4670 smss.exe 360 True True True True Okay Okay Okay
6010x01bcc830 System 4 True True True True Okay Okay Okay
6020x01a1bd78 csrss.exe 596 True True True True Okay True True
6030x01946020 svchost.exe 828 False True False False False False False
6040x019533c8 svchost.exe 924 False True True False False False False
6050x0185dda0 cmd.exe 940 Okay True Okay Okay Okay Okay Okay 2008-11-26 07:45:49 UTC+0000
6060x019467e0 services.exe 660 False True True False False False False
6070x0181b748 alg.exe 992 False True True False False False False
6080x0194f658 svchost.exe 1016 False True True False False False False
6090x019456e8 csrss.exe 592 False True True False Okay False False
610
611The "network_listene" process is hidden from the plist and psscan plugins. It has been unlinked from PsActiveProcessHead and also values used by the pool scanner have been modified.
612
6134. Run the getsids plugin against sample005.bin.
614
615 A) How many users are logged on?
616 B) What are their names?
617 C) Is there any evidence of privilege escalation attacks?
618
619The correct answer is: One user is logged on with SID S-1-5-21-219294376-1976090562-3929857903-1112 (saadmin). Many processes, including cmd.exe and explorer.exe, have gained domain admin:
620
621explorer.exe (1928): S-1-5-21-219294376-1976090562-3929857903-1112 (saadmin)
622explorer.exe (1928): S-1-5-21-219294376-1976090562-3929857903-513 (Domain Users)
623explorer.exe (1928): S-1-1-0 (Everyone)
624explorer.exe (1928): S-1-5-32-545 (Users)
625explorer.exe (1928): S-1-5-32-544 (Administrators)
626explorer.exe (1928): S-1-5-4 (Interactive)
627explorer.exe (1928): S-1-5-11 (Authenticated Users)
628explorer.exe (1928): S-1-5-15 (This Organization)
629explorer.exe (1928): S-1-5-5-0-46433 (Logon Session)
630explorer.exe (1928): S-1-2-0 (Local (Users with the ability to log in locally))
631explorer.exe (1928): S-1-5-21-219294376-1976090562-3929857903-512 (Domain Admins)
632
6335. Run the privs plugin against sample004.bin and sample005.bin.
634
635 A) In sample004.bin, which process(es) have the ability to load kernel drivers?
636 B) In sample005.bin, the dfssvc.exe process (PID 1608) enabled SeRestorePrivilege and SeBackupPrivilege. Do you think that's something to be worried about?
637
638The correct answer is:
639
640$ python vol.py -f sample004.bin privs -r driver | grep Enabled
641Volatility Foundation Volatility Framework 2.4 (Beta)
642 624 winlogon.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
643 684 lsass.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
644 1024 svchost.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
645 1356 spoolsv.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
646 1212 userinit.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
647 1096 explorer.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
648 2008 reader_sl.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
649 1796 AdobeARM.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
650 1120 cmd.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
651 1396 mdd.exe 10 SeLoadDriverPrivilege Present,Enabled Load and unload device drivers
652
653The fact that dfssvc.exe enabled SeRestorePrivilege and SeBackupPrivilege is not concerning, because dfssvc.exe is the Distributed File System Service process.
654
6556. Which process is currently accessing the ")!VoqA.I4" mutex in sample004.bin?
656
657The correct answer is: pid 1096
658
659----------------------------------------------------------------------
660Chapter 7: Processes Memory Internals
661----------------------------------------------------------------------
662
6631. Run the processmemory.exe program on one of your virtual machines. Dump memory while it's running. What is the process ID of processmemory.exe in your memory dump?
664
665C:\> processmemory.exe
666Heap allocation: 1531c0
667File mapping created at: 360000
668
669In this case, the pid is 928:
670
671$ python vol.py -f XPSP3-8c391840.vmem pslist -n processmemory
672Volatility Foundation Volatility Framework 2.4 (Beta)
673Offset(V) Name PID PPID Thds Hnds Sess Wow64 Start Exit
674---------- -------------------- ------ ------ ------ -------- ------ ------ ------------------------------ ------------------------------
6750x82226850 processmemory.e 928 1008 1 9 0 0 2014-07-12 17:58:07 UTC+0000
676
6772. What data does it write to its heap? Use volshell to investigate.
678
679The correct answer is: "hello from the heap!"
680
681From the program's output, we know the heap address is 1531c0, so you can investigate like this:
682
683$ python vol.py -f XPSP3-8c391840.vmem volshell -p 928
684Volatility Foundation Volatility Framework 2.4 (Beta)
685Current context: processmemory.e @ 0x82226850, pid=928, ppid=1008 DTB=0xa9401e0
686Python 2.7.6 (v2.7.6:3a1db0d2747e, Nov 10 2013, 00:42:54)
687Type "copyright", "credits" or "license" for more information.
688
689IPython 2.0.0 -- An enhanced Interactive Python.
690? -> Introduction and overview of IPython's features.
691%quickref -> Quick reference.
692help -> Python's own help system.
693object? -> Details about 'object', use 'object??' for extra details.
694
695In [1]: db(0x1531c0)
6960x001531c0 68 65 6c 6c 6f 20 66 72 6f 6d 20 74 68 65 20 68 hello.from.the.h
6970x001531d0 65 61 70 21 00 00 00 00 00 00 00 00 00 00 00 00 eap!............
6980x001531e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
6990x001531f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7000x00153200 c0 01 09 00 00 10 00 00 78 01 15 00 78 01 15 00 ........x...x...
7010x00153210 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7020x00153220 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7030x00153230 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
704
7053. Use the yarascan plugin to scan for the data you identified in Question 2. Does it show up in the expected location?
706
707It's found in two different locations:
708
709$ python vol.py -f XPSP3-8c391840.vmem yarascan -p 928 -Y "hello from the heap"
710Volatility Foundation Volatility Framework 2.4 (Beta)
711Rule: r1
712Owner: Process processmemory.e Pid 928
7130x0040a9b0 68 65 6c 6c 6f 20 66 72 6f 6d 20 74 68 65 20 68 hello.from.the.h
7140x0040a9c0 65 61 70 21 00 00 00 00 48 00 65 00 61 00 70 00 eap!....H.e.a.p.
7150x0040a9d0 20 00 61 00 6c 00 6c 00 6f 00 63 00 61 00 74 00 ..a.l.l.o.c.a.t.
7160x0040a9e0 69 00 6f 00 6e 00 3a 00 20 00 25 00 78 00 0a 00 i.o.n.:...%.x...
7170x0040a9f0 00 00 00 00 00 00 00 00 46 00 61 00 69 00 6c 00 ........F.a.i.l.
7180x0040aa00 65 00 64 00 20 00 74 00 6f 00 20 00 61 00 6c 00 e.d...t.o...a.l.
7190x0040aa10 6c 00 6f 00 63 00 61 00 74 00 65 00 20 00 68 00 l.o.c.a.t.e...h.
7200x0040aa20 65 00 61 00 70 00 20 00 6d 00 65 00 6d 00 6f 00 e.a.p...m.e.m.o.
7210x0040aa30 72 00 79 00 2e 00 00 00 46 00 69 00 6c 00 65 00 r.y.....F.i.l.e.
7220x0040aa40 20 00 6d 00 61 00 70 00 70 00 69 00 6e 00 67 00 ..m.a.p.p.i.n.g.
7230x0040aa50 20 00 63 00 72 00 65 00 61 00 74 00 65 00 64 00 ..c.r.e.a.t.e.d.
7240x0040aa60 20 00 61 00 74 00 3a 00 20 00 25 00 78 00 0a 00 ..a.t.:...%.x...
7250x0040aa70 00 00 00 00 46 00 61 00 69 00 6c 00 65 00 64 00 ....F.a.i.l.e.d.
7260x0040aa80 20 00 74 00 6f 00 20 00 6d 00 61 00 70 00 20 00 ..t.o...m.a.p...
7270x0040aa90 76 00 69 00 65 00 77 00 20 00 6f 00 66 00 20 00 v.i.e.w...o.f...
7280x0040aaa0 66 00 69 00 6c 00 65 00 2e 00 00 00 46 00 61 00 f.i.l.e.....F.a.
729Rule: r1
730Owner: Process processmemory.e Pid 928
7310x001531c0 68 65 6c 6c 6f 20 66 72 6f 6d 20 74 68 65 20 68 hello.from.the.h
7320x001531d0 65 61 70 21 00 00 00 00 00 00 00 00 00 00 00 00 eap!............
7330x001531e0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7340x001531f0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7350x00153200 c0 01 09 00 00 10 00 00 78 01 15 00 78 01 15 00 ........x...x...
7360x00153210 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7370x00153220 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7380x00153230 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7390x00153240 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7400x00153250 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7410x00153260 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7420x00153270 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7430x00153280 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7440x00153290 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7450x001532a0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
7460x001532b0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
747
748The first is at 0x0040a9b0 and is inside the process executable:
749
750$ python vol.py -f XPSP3-8c391840.vmem dlllist -p 928
751Volatility Foundation Volatility Framework 2.4 (Beta)
752************************************************************************
753processmemory.e pid: 928
754Command line : "C:\Documents and Settings\Administrator\Desktop\processmemory.exe"
755Service Pack 3
756
757Base Size LoadCount Path
758---------- ---------- ---------- ----
7590x00400000 0x11000 0xffff C:\Documents and Settings\Administrator\Desktop\processmemory.exe
7600x7c900000 0xb2000 0xffff C:\WINDOWS\system32\ntdll.dll
7610x7c800000 0xf6000 0xffff C:\WINDOWS\system32\kernel32.dll
762
763The second at 0x001531c0 is the one on the heap.
764
7654. The application's output tells you "File mapping created at..." Use vadinfo and determine the name of the file it maps into that address.
766
767The correct answer is: processmemory.exe (itself)
768
769In our example, the address was 0x360000. So you can do this:
770
771$ python vol.py -f XPSP3-8c391840.vmem vadinfo -n processmemory --addr 0x360000
772Volatility Foundation Volatility Framework 2.4 (Beta)
773************************************************************************
774Pid: 928
775VAD node @ 0x822dadb8 Start 0x00360000 End 0x0036cfff Tag Vad
776Flags: Protection: 1
777Protection: PAGE_READONLY
778ControlArea @820aa248 Segment e1156fc8
779NumberOfSectionReferences: 1 NumberOfPfnReferences: 13
780NumberOfMappedViews: 1 NumberOfUserReferences: 2
781Control Flags: Accessed: 1, File: 1, HadUserReference: 1, WasPurged: 1
782FileObject @821488a8, Name: \Documents and Settings\Administrator\Desktop\processmemory.exe
783First prototype PTE: e20bf800 Last contiguous PTE: e20bf860
784Flags2: CopyOnWrite: 1, Inherit: 1
785
7865. What VAD tag is used to map the file you identified on Step 4?
787
788The correct answer is: Vad
789
7906. How can you distinguish the mapping you identified in Question 4 from the mapping of the process' executable?
791
792The correct answer is: The one identified in Question 4 is PAGE_READONLY. The process' executable according to dlllist is at 0x00400000. This one is PAGE_EXECUTE_WRITECOPY:
793
794Pid: 928
795VAD node @ 0x823fcd38 Start 0x00400000 End 0x00410fff Tag Vad
796Flags: CommitCharge: 4, ImageMap: 1, Protection: 7
797Protection: PAGE_EXECUTE_WRITECOPY
798ControlArea @8208b908 Segment e2241428
799NumberOfSectionReferences: 1 NumberOfPfnReferences: 14
800NumberOfMappedViews: 1 NumberOfUserReferences: 2
801Control Flags: File: 1, HadUserReference: 1, Image: 1
802FileObject @822de140, Name: \Documents and Settings\Administrator\Desktop\processmemory.exe
803First prototype PTE: e2241468 Last contiguous PTE: fffffffc
804Flags2: Inherit: 1
805
8067. Run the zeusscan2 plugin against sample006.bin.
807
808 A) How many unique variants of Zeus are running?
809 B) Dump the associated VAD segment from one of the infected processes. Upload it to VirusTotal. Do you get any hits?
810
811The correct answer is: 4 unique variants (you can tell because there are 4 unique RC4 keys). Here is an example of one variant:
812
813$ python vol.py --plugins=contrib/plugins/malware -f sample006.bin zeusscan2
814Volatility Foundation Volatility Framework 2.4 (Beta)
815**************************************************
816Process : explorer.exe
817Pid : 1752
818Address : 50855936
819URL 0 : http://193.43.134.14/eu2.bin
820Identifier : JASONRESACC69_7875768F16073AAF
821Mutant key : 393228402
822XOR key : 537311486
823Registry : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Izozo
824 Value 1 : Kealtuuxd
825 Value 2 : Yrdii
826 Value 3 : Kebooqu
827Executable : Obyt\ihah.exe
828Data file : Ebupzu\uzugl.zuw
829Config RC4 key :
8300x03080000 4a ba 2c 63 eb 7c fc 45 c4 f3 b6 2d 31 29 21 2e J.,c.|.E...-1)!.
8310x03080010 53 0f 3f ef 9a 2a f8 82 96 6b e1 a2 3b 5f 34 fd S.?..*...k..;_4.
8320x03080020 a6 02 cc 39 0b 16 40 33 1f a1 dc af 93 9b 5b 94 ...9..@3......[.
8330x03080030 68 62 84 46 ca 64 8d 43 13 d4 d9 72 00 5c 2b bc hb.F.d.C...r.\+.
8340x03080040 f6 d7 88 91 24 9f bd 1e 7a 07 c5 6e 1a 4e 90 92 ....$...z..n.N..
8350x03080050 c1 42 0c 75 47 3a 9e 1d c2 ec 0d ed b8 71 b4 ab .B.uG:.......q..
8360x03080060 e6 5d e3 14 48 b9 e9 e8 b2 10 ee f4 e2 2f a4 09 .]..H......../..
8370x03080070 54 b7 95 be 50 99 8b 87 8f 37 9d fa f2 d5 b1 18 T...P....7......
8380x03080080 01 db 3c cf aa 70 e5 15 9c 5a 26 27 de da d8 d6 ..<..p...Z&'....
8390x03080090 59 a8 1b 30 cd 6c 78 c0 e7 c6 81 22 86 17 38 a7 Y..0.lx...."..8.
8400x030800a0 df 41 ad 4d 44 11 76 a3 52 a9 b3 6d 51 05 c9 b5 .A.MD.v.R..mQ...
8410x030800b0 85 49 77 c7 23 f7 3e 8a 03 69 ac 3d 4c 89 ff 58 .Iw.#.>..i.=L..X
8420x030800c0 dd 57 5e 97 98 f1 65 c3 7d f0 e0 20 e4 25 7e 7b .W^...e.}....%~{
8430x030800d0 b0 06 4b a5 c8 80 f9 f5 55 1c 7f 83 73 d1 66 fe ..K.....U...s.f.
8440x030800e0 8c 28 19 4f 60 36 0a 8e ce ae fb 0e 74 35 79 56 .(.O`6......t5yV
8450x030800f0 a0 08 ea bb 67 d3 d0 6a 12 6f 32 bf d2 04 cb 61 ....g..j.o2....a
8460x03080100 00 00 ..
847Credential RC4 key :
8480x03080000 6f e4 94 f2 f1 5e 5c c1 8c e8 66 c5 13 2a 23 39 o....^\...f..*#9
8490x03080010 84 36 6a 83 b2 55 6c 11 5a f3 b6 20 07 6d ba de .6j..Ul.Z....m..
8500x03080020 52 8e 34 bf 8a 05 0f 64 35 29 cb 5f ff 00 87 fc R.4....d5)._....
8510x03080030 b5 5b 67 b8 eb 1a 0e 1f 32 ae 54 3a 88 ed c3 51 .[g.....2.T:...Q
8520x03080040 40 14 3e 53 dc 7c a7 0b 79 26 e5 45 99 7d 1c d0 @.>S.|..y&.E.}..
8530x03080050 90 8f 80 95 71 58 41 5d f9 af 9e a1 6e ef 25 4e ....qXA]....n.%N
8540x03080060 48 2d b1 bd 33 ab d3 b7 4d 10 7e 44 65 7b cd 2f H-..3...M.~De{./
8550x03080070 ea 3f 2c ce 9a 9d db 31 b0 69 cf f7 e7 a6 82 a4 .?,....1.i......
8560x03080080 ad a3 30 9b 76 f0 f5 ac c2 fb 8b 4f fe 8d a8 04 ..0.v......O....
8570x03080090 86 a0 50 4c 4b e2 ec 60 e6 dd c6 42 cc 6b 89 57 ..PLK..`...B.k.W
8580x030800a0 d1 d8 78 4a 1d d7 9f e0 7a 75 e3 7f a2 77 85 2b ..xJ....zu...w.+
8590x030800b0 59 16 d6 d4 f4 93 ee 9c d2 03 be 2e 06 1b 56 70 Y.............Vp
8600x030800c0 d5 73 ca f8 fd 12 37 49 98 46 0d bb 96 c9 18 b9 .s....7I.F......
8610x030800d0 81 74 a9 3c 21 c4 da 38 0c 1e 27 0a c7 15 47 68 .t.<!..8..'...Gh
8620x030800e0 bc f6 91 fa 72 3d 01 e9 22 e1 09 c8 19 c0 aa b3 ....r=..".......
8630x030800f0 b4 08 17 3b 61 92 02 63 43 62 d9 df 97 24 28 a5 ...;a..cCb...$(.
8640x03080100 00 00 ..
865
866The address is 50855936 (0x3080000) according to the output. You can dump it like this:
867
868$ python vol.py --plugins=contrib/plugins/malware -f sample006.bin vaddump --base=0x3080000 -D .
869Volatility Foundation Volatility Framework 2.4 (Beta)
870Pid Process Start End Result
871---------- -------------------- ---------- ---------- ------
872 1752 explorer.exe 0x03080000 0x030b3fff ./explorer.exe.21b2020.0x03080000-0x030b3fff.dmp
873
874The uploaded file is available here:
875https://www.virustotal.com/en/file/0b117b2701c6004f5d3e8031d61a90c2561b6b82f742cfcf13574ee432888d86/analysis/
876
877VG Win32/Heri 20140622
878Ad-Aware Gen:Trojan.Heur.JP.nqY@aqKRZii 20140622
879AntiVir TR/Patched.Ren.Gen 20140622
880Avast Win32:Zbot-NRC [Trj] 20140622
881BitDefender Gen:Trojan.Heur.JP.nqY@aqKRZii 20140622
882Commtouch W32/Zbot.BZ.gen!Eldorado 20140622
883Emsisoft Gen:Trojan.Heur.JP.nqY@aqKRZii (B) 20140622
884F-Prot W32/Zbot.BZ.gen!Eldorado 20140622
885F-Secure Gen:Trojan.Heur.JP.nqY@aqKRZii 20140622
886GData Gen:Trojan.Heur.JP.nqY@aqKRZii 20140622
887Ikarus PWS.Win32 20140622
888MicroWorld-eScan Gen:Trojan.Heur.JP.nqY@aqKRZii 20140622
889Norman ZBot.DBB 20140622
890Rising PE:Stealer.Zbot!1.648A 20140622
891
892----------------------------------------------------------------------
893Chapter 8: Hunting Malware in Process Memory
894----------------------------------------------------------------------
895
8961. Use a Windows XP or 2003 system and open one or more Notepad processes. Either open existing text files or type into the document.
897
898 A) Run the notepad plugin against the system. Does it properly locate the document's text?
899 B) Extract the memory region containing the text to a separate file on disk
900
901The notepad plugin will tell you which memory range contains the data. You can pass that address to vaddump for extraction.
902
9032. Execute shelly.exe on a virtual machine. Dump memory while it's running.
904
905 A) What port does shelly.exe listen on?
906 B) Connect to shelly.exe using telnet or netcat. What do you see?
907 C) Analyze the standard handles on the memory dump. What process(es) have redirected handles?
908
909The correct answer is: TCP port 6922 - it returns a command prompt upon connection
910
911$ python vol.py -f memory.dmp pslist -n shelly
912Volatility Foundation Volatility Framework 2.4 (Beta)
913Offset(V) Name PID PPID Thds Hnds Sess Wow64 Start Exit
914---------- -------------------- ------ ------ ------ -------- ------ ------ ------------------------------ ------------------------------
9150x82387878 shelly.exe 2484 1008 1 32 0 0 2014-07-12 22:59:12 UTC+0000
916
917$ python vol.py -f memory.dmp sockets | grep 2484
918Volatility Foundation Volatility Framework 2.4 (Beta)
9190x82129050 2484 6922 6 TCP 0.0.0.0 2014-07-12 22:59:12 UTC+0000
920
921$ python vol.py -f memory.dmp volshell
922Volatility Foundation Volatility Framework 2.4 (Beta)
923Current context: System @ 0x825c8830, pid=4, ppid=0 DTB=0x319000
924Python 2.7.6 (v2.7.6:3a1db0d2747e, Nov 10 2013, 00:42:54)
925Type "copyright", "credits" or "license" for more information.
926
927IPython 2.0.0 -- An enhanced Interactive Python.
928? -> Introduction and overview of IPython's features.
929%quickref -> Quick reference.
930help -> Python's own help system.
931object? -> Details about 'object', use 'object??' for extra details.
932
933In [1]: for process in getprocs():
934 if str(process.ImageFileName) == "cmd.exe":
935 if process.Peb.ProcessParameters:
936 print process.UniqueProcessId, process.Peb.ProcessParameters.StandardInput, process.Peb.ProcessParameters.StandardOutput, process.Peb.ProcessParameters.StandardError
937 ...:
938
9392484 3 7 11
940292 3 7 11
941832 128 128 128 <==== this one has non standard handles
942
943Now you know process ID 832 is the instance of cmd.exe that's redirecting the remote commands.
944
9453. Analyze sample007.bin.
946
947 A) Are any processes hosting injected code? If so, which one(s)?
948 B) Have any processes been hollowed? If so, which one(s)?
949 C) Extract the injected code segments or hollowed process executables to disk for further static analysis.
950
951The correct answer is: services.exe (pid 668), svchost.exe (pid 940), lsass.exe (pid 868), lsass.exe (pid 1928) are hosting injected code. Here is some example output:
952
953$ python vol.py -f sample007.bin volshell
954Volatility Foundation Volatility Framework 2.4 (Beta)
955Process: services.exe Pid: 668 Address: 0x940000
956Vad Tag: Vad Protection: PAGE_EXECUTE_READWRITE
957Flags: Protection: 6
958
9590x00940000 90 06 94 00 c6 07 94 00 24 00 94 00 a5 04 00 00 ........$.......
9600x00940010 f2 04 94 00 48 06 00 00 c9 04 94 00 29 00 00 00 ....H.......)...
9610x00940020 00 00 c5 00 e8 13 00 00 00 5a 77 4d 61 70 56 69 .........ZwMapVi
9620x00940030 65 77 4f 66 53 65 63 74 69 6f 6e 00 5a 51 81 c1 ewOfSection.ZQ..
963
9640x940000 90 NOP
9650x940001 06 PUSH ES
9660x940002 94 XCHG ESP, EAX
9670x940003 00c6 ADD DH, AL
9680x940005 07 POP ES
969
970Process: services.exe Pid: 668 Address: 0x13f0000
971Vad Tag: Vad Protection: PAGE_EXECUTE_READWRITE
972Flags: Protection: 6
973
9740x013f0000 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 MZ..............
9750x013f0010 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 ........@.......
9760x013f0020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
9770x013f0030 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 ................
978
9790x13f0000 4d DEC EBP
9800x13f0001 5a POP EDX
9810x13f0002 90 NOP
9820x13f0003 0003 ADD [EBX], AL
9830x13f0005 0000 ADD [EAX], AL
9840x13f0007 000400 ADD [EAX+EAX], AL
985
986Process: svchost.exe Pid: 940 Address: 0xb70000
987Vad Tag: Vad Protection: PAGE_EXECUTE_READWRITE
988Flags: Protection: 6
989
9900x00b70000 29 87 7f ae 00 00 00 00 ff ff ff ff 77 35 00 01 )...........w5..
9910x00b70010 4b 00 45 00 52 00 4e 00 45 00 4c 00 33 00 32 00 K.E.R.N.E.L.3.2.
9920x00b70020 2e 00 44 00 4c 00 4c 00 2e 00 41 00 53 00 4c 00 ..D.L.L...A.S.L.
9930x00b70030 52 00 2e 00 30 00 33 00 36 00 30 00 63 00 38 00 R...0.3.6.0.c.8.
994
9950xb70000 29877fae0000 SUB [EDI+0xae7f], EAX
9960xb70006 0000 ADD [EAX], AL
9970xb70008 ff DB 0xff
9980xb70009 ff DB 0xff
9990xb7000a ff DB 0xff
10000xb7000b ff7735 PUSH DWORD [EDI+0x35]
10010xb7000e 0001 ADD [ECX], AL
1002
1003Process: lsass.exe Pid: 1928 Address: 0x680000
1004Vad Tag: Vad Protection: PAGE_EXECUTE_READWRITE
1005Flags: Protection: 6
1006
10070x00680000 90 06 68 00 c6 07 68 00 24 00 68 00 a5 04 00 00 ..h...h.$.h.....
10080x00680010 f2 04 68 00 48 06 00 00 c9 04 68 00 29 00 00 00 ..h.H.....h.)...
10090x00680020 00 00 6f 00 e8 13 00 00 00 5a 77 4d 61 70 56 69 ..o......ZwMapVi
10100x00680030 65 77 4f 66 53 65 63 74 69 6f 6e 00 5a 51 81 c1 ewOfSection.ZQ..
1011
10120x680000 90 NOP
10130x680001 06 PUSH ES
10140x680002 6800c60768 PUSH DWORD 0x6807c600
10150x680007 002400 ADD [EAX+EAX], AH
10160x68000a 6800a50400 PUSH DWORD 0x4a500
1017
1018Process: lsass.exe Pid: 1928 Address: 0x870000
1019Vad Tag: Vad Protection: PAGE_EXECUTE_READWRITE
1020Flags: Protection: 6
1021
10220x00870000 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 MZ..............
10230x00870010 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 ........@.......
10240x00870020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
10250x00870030 00 00 00 00 00 00 00 00 00 00 00 00 08 01 00 00 ................
1026
10270x870000 4d DEC EBP
10280x870001 5a POP EDX
10290x870002 90 NOP
10300x870003 0003 ADD [EBX], AL
10310x870005 0000 ADD [EAX], AL
10320x870007 000400 ADD [EAX+EAX], AL
1033
1034Also, the two lsass.exe processes are hollowed. According to the legit copy (pid 680) its image base should be 0x01000000. However, for pid 868 and 1928, the 0x01000000 memory range in ldrmodules is True/False/True with no mapped filename.
1035
1036$ python vol.py -f sample007.bin ldrmodules -p 680,868,1928
1037Volatility Foundation Volatility Framework 2.4 (Beta)
1038Pid Process Base InLoad InInit InMem MappedPath
1039-------- -------------------- ---------- ------ ------ ----- ----------
1040 680 lsass.exe 0x01000000 True False True \WINDOWS\system32\lsass.exe
1041 868 lsass.exe 0x00080000 False False False
1042 868 lsass.exe 0x7c900000 True True True \WINDOWS\system32\ntdll.dll
1043 868 lsass.exe 0x77e70000 True True True \WINDOWS\system32\rpcrt4.dll
1044 868 lsass.exe 0x7c800000 True True True \WINDOWS\system32\kernel32.dll
1045 868 lsass.exe 0x77fe0000 True True True \WINDOWS\system32\secur32.dll
1046 868 lsass.exe 0x7e410000 True True True \WINDOWS\system32\user32.dll
1047 868 lsass.exe 0x01000000 True False True
1048 868 lsass.exe 0x77f10000 True True True \WINDOWS\system32\gdi32.dll
1049 868 lsass.exe 0x77dd0000 True True True \WINDOWS\system32\advapi32.dll
1050 1928 lsass.exe 0x00080000 False False False
1051 1928 lsass.exe 0x7c900000 True True True \WINDOWS\system32\ntdll.dll
1052 1928 lsass.exe 0x773d0000 True True True \WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
1053 1928 lsass.exe 0x77f60000 True True True \WINDOWS\system32\shlwapi.dll
1054 1928 lsass.exe 0x771b0000 True True True \WINDOWS\system32\wininet.dll
1055 1928 lsass.exe 0x77a80000 True True True \WINDOWS\system32\crypt32.dll
1056 1928 lsass.exe 0x77fe0000 True True True \WINDOWS\system32\secur32.dll
1057 1928 lsass.exe 0x77c00000 True True True \WINDOWS\system32\version.dll
1058 1928 lsass.exe 0x01000000 True False True
1059 1928 lsass.exe 0x5b860000 True True True \WINDOWS\system32\netapi32.dll
1060 1928 lsass.exe 0x77e70000 True True True \WINDOWS\system32\rpcrt4.dll
1061 1928 lsass.exe 0x71ab0000 True True True \WINDOWS\system32\ws2_32.dll
1062 1928 lsass.exe 0x71ad0000 True True True \WINDOWS\system32\wsock32.dll
1063 1928 lsass.exe 0x774e0000 True True True \WINDOWS\system32\ole32.dll
1064 1928 lsass.exe 0x7e410000 True True True \WINDOWS\system32\user32.dll
1065 1928 lsass.exe 0x77f10000 True True True \WINDOWS\system32\gdi32.dll
1066 1928 lsass.exe 0x77120000 True True True \WINDOWS\system32\oleaut32.dll
1067 1928 lsass.exe 0x76d60000 True True True \WINDOWS\system32\iphlpapi.dll
1068 1928 lsass.exe 0x769c0000 True True True \WINDOWS\system32\userenv.dll
1069 1928 lsass.exe 0x7c800000 True True True \WINDOWS\system32\kernel32.dll
1070 1928 lsass.exe 0x76bf0000 True True True \WINDOWS\system32\psapi.dll
1071 1928 lsass.exe 0x77c10000 True True True \WINDOWS\system32\msvcrt.dll
1072 1928 lsass.exe 0x77dd0000 True True True \WINDOWS\system32\advapi32.dll
1073 1928 lsass.exe 0x7c9c0000 True True True \WINDOWS\system32\shell32.dll
1074 1928 lsass.exe 0x00870000 True True True
1075 1928 lsass.exe 0x76f20000 True True True \WINDOWS\system32\dnsapi.dll
1076 1928 lsass.exe 0x5d090000 True True True \WINDOWS\system32\comctl32.dll
1077 1928 lsass.exe 0x71aa0000 True True True \WINDOWS\system32\ws2help.dll
1078 1928 lsass.exe 0x77b20000 True True True \WINDOWS\system32\msasn1.dll
1079
1080You can dump the memory range like this:
1081
1082$ python vol.py sample007.bin procdump --memory -D . -p 868,1928
1083Volatility Foundation Volatility Framework 2.4 (Beta)
1084Process(V) ImageBase Name Result
1085---------- ---------- -------------------- ------
10860x81c498c8 0x01000000 lsass.exe OK: executable.868.exe
10870x81c47c00 0x01000000 lsass.exe OK: executable.1928.exe
1088
10894. Extract storytime.dll.zip (password: infected).
1090
1091 A) Can you analyze the file in IDA pro, PE analyzers, etc?
1092 B) Run the DLL on a 64-bit system and dump memory while it's running.
1093 C) Determine the load address of the DLL and unpack it from memory.
1094
1095The correct answer is: No, you cannot initially analyze it statically in IDA Pro. Run it in the VM with "rundll32 <PATHTODLL>,ExportName" and then use dlldump to extract the unpacked copy.
1096
10975. Perform the following steps:
1098
1099 A) Create an account on virusshare.com
1100 B) Download some malware samples (packed or unpacked)
1101 C) Run them in your virtual machine and develop Yara signatures for detecting their presence
1102 D) Create memory dumps and scan for your signatures with the yarascan plugin
1103
1104The correct answer is: N/A
1105
1106----------------------------------------------------------------------
1107Chapter 9: Event Logs
1108----------------------------------------------------------------------
1109
11101. What process on XP and 2003 stores mapped copies of the event log files?
1111
1112 A) evtsvc.exe
1113 B) System
1114 C) services.exe
1115 D) mmc.exe
1116
1117The correct answer is: C
1118
11192. Which of the following statement(s) are False?
1120
1121 A) Event logs can be cleared
1122 B) Reconstructing event logs from memory may yield incomplete results, because not all records are mapped into memory (or they're paged)
1123 C) If the Security event log is empty, you should check the logging policy in the registry
1124 D) Volatility natively parses Vista and later event log formats
1125
1126The correct answer is: D
1127
11283. Use the evtlogs plugin against an XP or 2003 memory image.
1129
1130 A) Analyze the output text files for particular event IDs
1131 B) Export the raw logs and process them with a tool external to Volatility
1132
1133The correct answer is: N/A
1134
11354. Analyze a Vista or later memory image.
1136
1137 A) Extract the event logs with the "dumpfiles" plugin
1138 B) Analyze the event logs with a tool external to Volatility
1139
1140The correct answer is: N/A
1141
1142----------------------------------------------------------------------
1143Chapter 10: Registry in Memory
1144----------------------------------------------------------------------
1145
11461. Run the hivelist plugin on sample004.bin.
1147
1148 A) What's the virtual address of the HKEY_LOCAL_MACHINE\SOFTWARE hive?
1149 B) What's the virtual address of the "administrator" user's HKEY_CURRENT_USER hive?
1150
1151The correct answer is: A) 0xe14596b8 and B) 0xe10b9008
1152
1153$ python vol.py -f sample004.bin hivelist
1154Volatility Foundation Volatility Framework 2.4 (Beta)
1155Virtual Physical Name
1156---------- ---------- ----
11570xe1b67350 0x13f3c350 \Device\HarddiskVolume1\Documents and Settings\administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
11580xe10b9008 0x0cf25008 \Device\HarddiskVolume1\Documents and Settings\administrator\NTUSER.DAT
11590xe175b9e8 0x082589e8 \Device\HarddiskVolume1\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
11600xe1740b60 0x08241b60 \Device\HarddiskVolume1\Documents and Settings\LocalService\NTUSER.DAT
11610xe1682b60 0x07a02b60 \Device\HarddiskVolume1\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
11620xe16d9008 0x07e72008 \Device\HarddiskVolume1\Documents and Settings\NetworkService\NTUSER.DAT
11630xe14596b8 0x069876b8 \Device\HarddiskVolume1\WINDOWS\system32\config\software
11640xe1460008 0x06931008 \Device\HarddiskVolume1\WINDOWS\system32\config\default
11650xe1460b60 0x06931b60 \Device\HarddiskVolume1\WINDOWS\system32\config\SAM
11660xe1459b60 0x06987b60 \Device\HarddiskVolume1\WINDOWS\system32\config\SECURITY
11670xe1343b60 0x02a49b60 [no name]
11680xe1035b60 0x02739b60 \Device\HarddiskVolume1\WINDOWS\system32\config\system
11690xe102e008 0x02733008 [no name]
1170
11712. Use the printkey plugin to check the "Microsoft\Windows\CurrentVersion\Run" key in both identified hives above. Do you see any entries that are worth further investigation?
1172
1173The correct answer is: the svchosts.exe entry in HKLM (the real filename is svchost.exe)
1174
1175$ python vol.py -f sample004.bin printkey -o 0xe14596b8 -K "Microsoft\Windows\CurrentVersion\Run"
1176Volatility Foundation Volatility Framework 2.4 (Beta)
1177Legend: (S) = Stable (V) = Volatile
1178
1179----------------------------
1180Registry: User Specified
1181Key name: Run (S)
1182Last updated: 2012-04-28 01:59:22 UTC+0000
1183
1184Subkeys:
1185 (S) OptionalComponents
1186
1187Values:
1188REG_SZ Adobe Reader Speed Launcher : (S) "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
1189REG_SZ Adobe ARM : (S) "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
1190REG_SZ svchosts : (S) C:\WINDOWS\system32\svchosts.exe
1191
11923. Analyze sample007.bin. Determine which services were most recently added or modified.
1193
1194The correct answer is: (see the example in Chapter 12 - page 354)
1195
11964. Extract the cached password hashes (using hashdump) on some of your memory samples. Load them into a password cracker to determine the plain text password (if possible).
1197
1198The correct answer is: N/A
1199
12005. Execute the following steps:
1201
1202 A) On your system, launch some programs, browse to some directories in Explorer, etc
1203 B) Create a memory dump of your system
1204 C) Run the shimcache, userassist, and shellbags plugins. Do you see any artifacts of the actions you performed in A?
1205 D) Run the plugins on some memory images from prior investigations
1206
1207The correct answer is: N/A
1208
1209----------------------------------------------------------------------
1210Chapter 11: Networking
1211----------------------------------------------------------------------
1212
12131. What is one potential way to hide winsock network activity from memory forensics tools?
1214
1215 A) Hook the DeviceIoControl API in user mode
1216 B) Hook the IRP_MJ_DEVICE_CONTROL of tcpip.sys in kernel mode
1217 C) Unlink the singly linked list of connection or socket structures in kernel mode
1218 D) Use an NDIS driver
1219
1220The correct answer is: D
1221
12222. TCP client and server applications both create _ADDRESS_OBJECT (sockets).
1223
1224 True or False?
1225
1226The correct answer is: True
1227
12283. Was RDP enabled on sample004.bin?
1229
1230The correct answer is: Yes, you can see the open port with sockets:
1231
1232$ python vol.py -f sample004.bin sockets | grep 3389
1233Volatility Foundation Volatility Framework 2.4 (Beta)
12340x821fde98 852 3389 6 TCP 0.0.0.0 2012-04-28 01:57:04 UTC+0000
1235
12364. How many active connections did sample004.bin have? What websites (port 80 or 443) did it access in the recent past?
1237
1238The correct answer is: 2 active connections (TCP 139 and 443).
1239
1240$ python vol.py -f sample004.bin connections
1241Volatility Foundation Volatility Framework 2.4 (Beta)
1242Offset(V) Local Address Remote Address Pid
1243---------- ------------------------- ------------------------- ---
12440x8201ce68 172.16.150.20:1365 172.16.150.10:139 4
12450x82018e00 172.16.150.20:1424 221.54.197.32:443 1096
1246
1247It communicated with several web servers recently:
1248
1249$ python vol.py -f sample004.bin connscan | egrep '(:80|:443)'
1250Volatility Foundation Volatility Framework 2.4 (Beta)
12510x02018e00 172.16.150.20:1424 221.54.197.32:443 1096
12520x02168718 172.16.150.20:1428 199.7.59.190:80 1796
12530x0222aa40 172.16.150.20:1427 199.7.52.190:80 1796
12540x0c3bfa40 172.16.150.20:1427 199.7.52.190:80 1796
12550x1cd75a40 172.16.150.20:1427 199.7.52.190:80 1796
12560x1df7aa40 172.16.150.20:1427 199.7.52.190:80 1796
12570x1f3a1a40 172.16.150.20:1427 199.7.52.190:80 1796
1258
12595. Run Bulk Extractor or CapLoader against a memory image. Can you trace back the network activity to process(es) or driver(s) that generated it?
1260
1261The correct answer is: N/A
1262
12636. Perform the following steps:
1264
1265 A) Use Internet Explorer v4 - v9 on one of your virtual machines to access web pages
1266 B) Visit an FTP site with Windows Explorer
1267 C) Acquire memory from your system
1268 D) Use the iehistory plugin against the IE and Explorer process to gather artifacts. Does it contain what you expect?
1269
1270The correct answer is: N/A
1271
12727. Use the filescan and dumpfiles plugins to extract and analyze the HOSTS file from some of your memory dumps.
1273
1274Here is an example:
1275
1276$ python vol.py -f sample007.bin filescan | grep hosts
1277Volatility Foundation Volatility Framework 2.4 (Beta)
12780x0000000002192f90 1 0 R--rw- \Device\HarddiskVolume1\WINDOWS\system32\drivers\etc\hosts
1279
1280$ python vol.py -f sample007.bin dumpfiles -Q 0x0000000002192f90 -D . --name
1281Volatility Foundation Volatility Framework 2.4 (Beta)
1282DataSectionObject 0x02192f90 None \Device\HarddiskVolume1\WINDOWS\system32\drivers\etc\hosts
1283
1284$ strings file.None.0x8211f1f8.hosts.dat
1285# Copyright (c) 1993-1999 Microsoft Corp.
1286# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
1287# This file contains the mappings of IP addresses to host names. Each
1288# entry should be kept on an individual line. The IP address should
1289# be placed in the first column followed by the corresponding host name.
1290# The IP address and the host name should be separated by at least one
1291# space.
1292# Additionally, comments (such as these) may be inserted on individual
1293# lines or following the machine name denoted by a '#' symbol.
1294# For example:
1295# 102.54.94.97 rhino.acme.com # source server
1296# 38.25.63.10 x.acme.com # x client host
1297127.0.0.1 localhost
1298
1299----------------------------------------------------------------------
1300Chapter 12: Services
1301----------------------------------------------------------------------
1302
13031. Which of the following is NOT a reason why malware uses services:
1304
1305 A) For persistence
1306 B) To load kernel drivers
1307 C) To get code running inside services.exe
1308 D) To hide among the various svchost.exe processes that you typically see
1309
1310The correct answer is: C
1311
13122. Malware that leverages services must directly or indirectly call CreateService and StartService eventually.
1313
1314 True or False?
1315
1316The correct answer is: False (it can call native APIs such as NdrClientCall and bypass the higher-level APIs)
1317
13183. Perform the following steps:
1319
1320 A) Run servicedll_whitelist.py on one of your systems (make sure to install Pywin32 first)
1321 B) Dump memory from the system
1322 C) Run svcscan with the --verbose flag to see the ServiceDll values
1323 D) Can you spot any discrepancies?
1324
1325The correct answer is: N/A
1326
13274. Perform the following steps:
1328
1329 A) Create a memory dump of your Windows XP or 2003 system
1330 B) Download the UnlinkServiceRecord.zip tool from https://code.google.com/p/malwarecookbook/source/browse/trunk/17/10/UnlinkServiceRecord.zip
1331 C) Choose a service that's running and unlink it with the tool
1332 D) Type "sc query NAME" on command line (where NAME is the name of the service you unlinked). Can the system find any information on that service?
1333 E) Dump memory a second time
1334 F) Use the svcscan plugin to detect the unlinked service
1335
1336The correct answer is: N/A (see the "Revealing Hidden Services" section of Chapter 12)
1337
13385. Analyze sample001.bin.
1339
1340 A) What new service did the malware install? How do you know it's new?
1341 B) What is the path to the malicious DLL that implements the service?
1342 C) Google the name of the service. Is it related to any known exploits or threat groups?
1343 D) Is the service running? If so, what is the host process ID?
1344 E) Dump the malicious DLL from memory for static analysis
1345
1346The correct answer is: The malware created 6to4. You can tell it's new because alphabetically 6to4 should be near the top of the list, but svcscan shows its order is at the very end (after xmlprov). Thus, 6to4 was added after the last reboot.
1347
1348$ python vol.py -f sample001.bin svcscan
1349
1350[snip]
1351
1352Offset: 0x389cd0
1353Order: 227
1354Start: SERVICE_DEMAND_START
1355Process ID: -
1356Service Name: xmlprov
1357Display Name: Network Provisioning Service
1358Service Type: SERVICE_WIN32_SHARE_PROCESS
1359Service State: SERVICE_STOPPED
1360Binary Path: -
1361
1362Offset: 0x389d60
1363Order: 228
1364Start: SERVICE_AUTO_START
1365Process ID: 1024
1366Service Name: 6to4
1367Display Name: Microsoft Device Manager
1368Service Type: SERVICE_WIN32_SHARE_PROCESS
1369Service State: SERVICE_RUNNING
1370Binary Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
1371
1372Using the --verbose flag to svcscan will show the ServiceDll path of C:\WINDOWS\system32\6to4ex.dll
1373
1374The 6to4 service is not associated with any particular threat group per se, although many have abused it in the past. The 6to4 service is a legitimate component of the OS (helps migrate IPv4 to IPv6), but it's just often hijacked.
1375
1376The service is currently running with PID 1024. You can dump the DLL with dlldump.
1377
1378----------------------------------------------------------------------
1379Chapter 13: Kernel Forensics and Rootkits
1380----------------------------------------------------------------------
1381
13821. If a kernel module unlinks from the PsLoadedModuleList, manipulates the MmLd pool tags, and zeroes out its PE header, you can still find the malicious rootkit code how?
1383
1384 A) By following thread start addresses
1385 B) By following kernel callbacks
1386 C) By following timer DPCs
1387 D) By analyzing corresponding driver objects
1388 E) All of the above
1389
1390The correct answer is: E
1391
13922. You may not find entries in the "services" key of the registry for drivers loaded via NtLoadDriver.
1393
1394 True or False?
1395
1396The correct answer is: True (because malware can delete the registry keys after loading the driver)
1397
13983. Perform the following steps:
1399
1400 A) Run Process Explorer from Sysinternals on a 64-bit Windows system
1401 B) Dump memory of the system
1402 C) Run the modules plugin. Does Process Explorer show up at the start or end of the list? Why?
1403 D) Run the callbacks plugin. What types of callbacks does Process Explorer use?
1404
1405The correct answer is: Yes, Process Explorer kernel module will show up near the end of the list, since the modules added sequentially. Process Explorer uses process creation, thread creation, and image load callbacks.
1406
14074. Perform the following steps on sample008.bin:
1408
1409 A) Determine if the system is infected
1410 B) Identify and extract the rootkit code (if any) from kernel memory
1411 C) What is/was the name of the driver file on disk?
1412 D) For extra credit, find the base address of the rootkit driver in memory, extract it, and repair the PE header so you can load it in IDA Pro for reverse engineering.
1413
1414Here are some of the ways you can detect this rootkit. First, there are various orphan threads:
1415
1416$ python vol.py -f sample008.bin threads -F OrphanThread
1417Volatility Foundation Volatility Framework 2.4 (Beta)
1418[x86] Gathering all referenced SSDTs from KTHREADs...
1419Finding appropriate address space for tables...
1420------
1421ETHREAD: 0xff1f92b0 Pid: 4 Tid: 1648
1422Tags: OrphanThread,SystemThread
1423Created: 2010-08-15 19:26:13 UTC+0000
1424Exited: 1970-01-01 00:00:00 UTC+0000
1425Owning Process: System
1426Attached Process: System
1427State: Waiting:DelayExecution
1428BasePriority: 0x8
1429Priority: 0x8
1430TEB: 0x00000000
1431StartAddress: 0xf2edd150 UNKNOWN
1432ServiceTable: 0x80552180
1433 [0] 0x80501030
1434 [1] 0x00000000
1435 [2] 0x00000000
1436 [3] 0x00000000
1437Win32Thread: 0x00000000
1438CrossThreadFlags: PS_CROSS_THREAD_FLAGS_SYSTEM
14390xf2edd150 803d782aeff200 CMP BYTE [0xf2ef2a78], 0x0
14400xf2edd157 7437 JZ 0xf2edd190
14410xf2edd159 56 PUSH ESI
14420xf2edd15a bef0d0edf2 MOV ESI, 0xf2edd0f0
14430xf2edd15f ff35702aeff2 PUSH DWORD [0xf2ef2a70]
14440xf2edd165 ff DB 0xff
14450xf2edd166 15 DB 0x15
14460xf2edd167 0c DB 0xc
1447------
1448ETHREAD: 0x0113e4a8 Pid: 4 Tid: 600
1449Tags: OrphanThread,ScannerOnly,SystemThread
1450Created: 2010-08-11 06:09:35 UTC+0000
1451Exited: 2010-08-11 06:09:35 UTC+0000
1452Owning Process: System
1453Attached Process: System
1454State: Terminated
1455BasePriority: 0x8
1456Priority: 0x18
1457TEB: 0x00000000
1458StartAddress: 0xf2fe2150 UNKNOWN
1459ServiceTable: 0x80552180
1460 [0] 0x80501030
1461 [1] 0x00000000
1462 [2] 0x00000000
1463 [3] 0x00000000
1464Win32Thread: 0x00000000
1465CrossThreadFlags: PS_CROSS_THREAD_FLAGS_SYSTEM, PS_CROSS_THREAD_FLAGS_TERMINATED
1466
1467------
1468ETHREAD: 0xff2674a0 Pid: 4 Tid: 1720
1469Tags: OrphanThread,SystemThread
1470Created: 2010-08-15 19:26:13 UTC+0000
1471Exited: 1970-01-01 00:00:00 UTC+0000
1472Owning Process: System
1473Attached Process: System
1474State: Waiting:DelayExecution
1475BasePriority: 0x8
1476Priority: 0x8
1477TEB: 0x00000000
1478StartAddress: 0xf2edc54e UNKNOWN
1479ServiceTable: 0x80552180
1480 [0] 0x80501030
1481 [1] 0x00000000
1482 [2] 0x00000000
1483 [3] 0x00000000
1484Win32Thread: 0x00000000
1485CrossThreadFlags: PS_CROSS_THREAD_FLAGS_SYSTEM
14860xf2edc54e 803d682aeff200 CMP BYTE [0xf2ef2a68], 0x0
14870xf2edc555 744e JZ 0xf2edc5a5
14880xf2edc557 56 PUSH ESI
14890xf2edc558 57 PUSH EDI
14900xf2edc559 be9ac3edf2 MOV ESI, 0xf2edc39a
14910xf2edc55e bfecc3edf2 MOV EDI, 0xf2edc3ec
14920xf2edc563 ff DB 0xff
14930xf2edc564 35 DB 0x35
14940xf2edc565 b4 DB 0xb4
1495------
1496ETHREAD: 0x80f334a8 Pid: 4 Tid: 1992
1497Tags: OrphanThread,SystemThread
1498Created: 2010-08-15 19:26:13 UTC+0000
1499Exited: 1970-01-01 00:00:00 UTC+0000
1500Owning Process: System
1501Attached Process: System
1502State: Waiting:DelayExecution
1503BasePriority: 0x8
1504Priority: 0x8
1505TEB: 0x00000000
1506StartAddress: 0xf2edba46 UNKNOWN
1507ServiceTable: 0x80552180
1508 [0] 0x80501030
1509 [1] 0x00000000
1510 [2] 0x00000000
1511 [3] 0x00000000
1512Win32Thread: 0x00000000
1513CrossThreadFlags: PS_CROSS_THREAD_FLAGS_SYSTEM
15140xf2edba46 803d542aeff200 CMP BYTE [0xf2ef2a54], 0x0
15150xf2edba4d 745e JZ 0xf2edbaad
15160xf2edba4f 53 PUSH EBX
15170xf2edba50 8b1d0ce1edf2 MOV EBX, [0xf2ede10c]
15180xf2edba56 56 PUSH ESI
15190xf2edba57 57 PUSH EDI
15200xf2edba58 bf3eb9edf2 MOV EDI, 0xf2edb93e
15210xf2edba5d be DB 0xbe
1522
1523All of the StartAddress fields tell you where the rootkit code exists.
1524
1525There is a suspiciously named driver:
1526
1527$ python vol.py -f sample008.bin driverscan
1528Volatility Foundation Volatility Framework 2.4 (Beta)
1529Offset(P) #Ptr #Hnd Start Size Service Key Name Driver Name
1530------------------ -------- -------- ---------- ---------- -------------------- ------------ -----------
15310x0000000001058388 4 0 0xfc76b000 0x6b00 Fdc Fdc \Driver\Fdc
15320x0000000001058e28 4 0 0xfc93b000 0x3c80 serenum serenum \Driver\serenum
15330x0000000001059258 4 0 0xfc54b000 0xfd80 Serial Serial \Driver\Serial
15340x00000000010593e8 4 0 0xfc121000 0x13900 Parport Parport \Driver\Parport
15350x000000000106fca0 3 0 0xf3a85000 0x20f00 IpNat IpNat \Driver\IpNat
15360x000000000108ef38 2 0 0x00000000 0x0 tmryq....sys
1537[snip]
1538
1539Unfortunately the driver start and size have been zeroed (potentially for anti-dumping). The filescan plugin shows the original path to the driver:
1540
1541$ python vol.py -f sample008.bin filescan | grep tmr
1542Volatility Foundation Volatility Framework 2.4 (Beta)
15430x0000000001094ea0 1 0 R--r-d \Device\HarddiskVolume1\WINDOWS\system32\drivers\tmryqyrznr2.sys
1544
1545You can extract a copy with dumpfiles:
1546
1547$ python vol.py -f sample008.bin dumpfiles -Q 0x0000000001094ea0 -D . --name
1548Volatility Foundation Volatility Framework 2.4 (Beta)
1549ImageSectionObject 0x01094ea0 None \Device\HarddiskVolume1\WINDOWS\system32\drivers\tmryqyrznr2.sys
1550DataSectionObject 0x01094ea0 None \Device\HarddiskVolume1\WINDOWS\system32\drivers\tmryqyrznr2.sys
1551
15525. Analyze sample007.bin:
1553
1554 A) Does this rootkit work by hooking IRP functions or using layered devices?
1555 B) What functionality or capabilities can you uncover?
1556 C) Are any of the kernel modules digitally signed?
1557 D) Does the rootkit install any callbacks or timers?
1558 E) Extract the rootkit code, fix the PE header (if necessary), and load into IDA Pro. Label the malicious functions based on addresses you see in the answers to A and D.
1559
1560The correct answer is: (this memory image is infected with stuxnex, you can read about the artifacts here: http://mnin.blogspot.com/2011/06/examining-stuxnets-footprint-in-memory.html)
1561
1562----------------------------------------------------------------------
1563Chapter 14: Windows GUI Subsystem, Part I
1564----------------------------------------------------------------------
1565
15661. Perform the following steps:
1567
1568 A) Configure one of your virtual machines with multiple users
1569 B) Log onto the console with one user account and RDP with another user account
1570 C) Acquire a memory dump from the system
1571 D) Run the screenshots plugin. Do you see each user's desktop?
1572 E) Run the session plugin. Can you tell which user is logged in via RDP?
1573
1574The correct answer is: To answer E, look at which session has rdpclip.exe and RDPDD.dll running. Then use the getsids plugin to translate the SIDs of those processes to a user name.
1575
15762. Perform the following steps:
1577
1578 A) Launch Sysinternals Desktops and create some additional desktops
1579 B) Execute some applications on each desktop
1580 C) Use WinLister or Spy++ on your main desktop. Can you see the windows in other desktops?
1581 D) Run the desktops Volatility plugin. Do you see the new desktops? Are the proper threads/processes associated with the proper desktops?
1582 E) Run the windows and wintree plugins.
1583
1584The correct answer is: Using WinLister or Spy++ will not show the windows on other desktops.
1585
15863. Analyze sample007.bin.
1587
1588 A) Which window is monitoring USB insertions?
1589 B) What is the address of the malicious window procedure?
1590 C) What is the window's class atom (integer) value?
1591 D) Run the atoms or atomscan plugin. Do you see the class atom string?
1592
1593The correct answer is: AFX64c313. See the "Artifact 17 and 18: Windows & Classes" section of http://mnin.blogspot.com/2011/06/examining-stuxnets-footprint-in-memory.html
1594
1595----------------------------------------------------------------------
1596Chapter 15: Windows GUI Subsystem, Part II
1597----------------------------------------------------------------------
1598
15991. Perform the following steps on sample009.bin:
1600
1601 A) Run the messagehooks plugin. Are there any global hooks?
1602 B) What type of messages are being filtered/hooked?
1603 C) What is the full path to the injected hook DLL?
1604 D) What is the address of the hook handler function inside the DLL?
1605 E) Extract the malicious DLL and analyze the handler in IDA Pro. What is the purpose of the hook?
1606
1607The correct answer is: Yes, the hooks are global (HF_GLOBAL flag). The WH_GETMESSAGE is being filtered. The DLL is on the "Mal Ware" user's desktop. The hook address is at RVA 0x00001fd9. You can dump the DLL with dlldump and then load it in IDA Pro and go to address BASE + 0x00001fd9. The function just calls CallNextHookEx (no payload, it just exists to inject the DLL into the target processes).
1608
1609$ python vol.py -f sample009.bin messagehooks
1610Volatility Foundation Volatility Framework 2.4 (Beta)
1611Offset(V) Sess Desktop Thread Filter Flags Function Module
1612---------- ------ -------------------- ------------------------------ -------------------- -------------------- ---------- ------
16130xbc693988 0 WinSta0\Default <any> WH_GETMESSAGE HF_ANSI, HF_GLOBAL 0x00001fd9 C:\Documents and Settings\Mal Ware\Desktop\Dll.dll
16140xbc693988 0 WinSta0\Default 384 (KernelDrv.exe 352) WH_GETMESSAGE HF_ANSI, HF_GLOBAL 0x00001fd9 C:\Documents and Settings\Mal Ware\Desktop\Dll.dll
16150xbc693988 0 WinSta0\Default 2024 (lanmanwrk.exe 920) WH_GETMESSAGE HF_ANSI, HF_GLOBAL 0x00001fd9 C:\Documents and Settings\Mal Ware\Desktop\Dll.dll
16160xbc693988 0 WinSta0\Default 1392 (lanmanwrk.exe 920) WH_GETMESSAGE HF_ANSI, HF_GLOBAL 0x00001fd9 C:\Documents and Settings\Mal Ware\Desktop\Dll.dll
16170xbc693988 0 WinSta0\Default 1584 (explorer.exe 1624) WH_GETMESSAGE HF_ANSI, HF_GLOBAL 0x00001fd9 C:\Documents and Settings\Mal Ware\Desktop\Dll.dll
16180xbc693988 0 WinSta0\Default 252 (VMwareUser.exe 1768) WH_GETMESSAGE HF_ANSI, HF_GLOBAL 0x00001fd9 C:\Documents and Settings\Mal Ware\Desktop\Dll.dll
1619
16202. Perform the following steps on your own virtual machine:
1621
1622 A) Copy message_hook_installer.exe and message_hooklib.dll to your machine
1623 B) Double-click the exe file
1624 C) Acquire a memory dump
1625 D) Perform the same steps as question #1
1626
1627The correct answer is: N/A
1628
16293. Perform the following steps on your own virtual machine:
1630
1631 A) Copy some text to your clipboard
1632 B) Copy a file from Windows Explorer
1633 C) Acquire a memory dump
1634 D) Run the clipboard plugin. Do you see what you expect?
1635
1636The correct answer is: N/A
1637
1638----------------------------------------------------------------------
1639Chapter 16: Disk Artifacts in Memory
1640----------------------------------------------------------------------
1641
16421. Run the mftparser plugin against some of your memory dumps. Collect the output in body file format and build a timeline. What were the most recently accessed and created files?
1643
1644You can do this like:
1645
1646$ python vol.py -f MEMORY.DMP --profile=PROFILE mftparser --output=body --output-file=body.txt
1647$ mactime -b body.txt -d -z UTC > timeline.txt
1648
16492. Analyze sample004.bin with mftparser. Specifically, extract the MFT-resident file data. Can you find any attacker scripts?
1650
1651f.txt:
1652
1653MFT entry found at offset 0x15938800
1654Type: In Use & File
1655Record Number: 12030
1656Number of fixup array vals 3
1657Link count: 1
1658Sequence Value: 0x3
1659Fixup Array: 0x9 0x0 0x0
1660
1661$STANDARD_INFO
1662Creation Modified MFT Altered Access Date Type
1663-------------------- -------------------- -------------------- -------------------- ----
16642012-04-28 02:01:43 2012-04-28 02:01:43 2012-04-28 02:01:43 2012-04-28 02:01:43 Archive
1665
1666$FILE_NAME
1667Creation Modified MFT Altered Access Date Name/Path
1668-------------------- -------------------- -------------------- -------------------- ---------
16692012-04-28 02:01:43 2012-04-28 02:01:43 2012-04-28 02:01:43 2012-04-28 02:01:43 f.txt
1670Full Path: WINDOWS\system32\systems\f.txt
1671
1672$DATA
16730x00000000: 7b 00 00 00 18 00 00 00 6f 70 65 6e 20 36 36 2e {.......open.66.
16740x00000010: 33 32 2e 31 31 39 2e 33 38 0d 0a 6a 61 63 6b 0d 32.119.38..jack.
16750x00000020: 0a 32 61 77 65 73 30 6d 65 0d 0a 6c 63 64 20 63 .2awes0me..lcd.c
16760x00000030: 3a 5c 57 49 4e 44 4f 57 53 5c 53 79 73 74 65 6d :\WINDOWS\System
16770x00000040: 33 32 5c 73 79 73 74 65 6d 73 0d 0a 63 64 20 20 32\systems..cd..
16780x00000050: 2f 68 6f 6d 65 2f 6a 61 63 6b 0d 0a 62 69 6e 61 /home/jack..bina
16790x00000060: 72 79 0d 0a 6d 70 75 74 20 22 2a 2e 74 78 74 22 ry..mput."*.txt"
16800x00000070: 0d 0a 64 69 73 63 6f 6e 6e 65 63 74 0d 0a 62 79 ..disconnect..by
16810x00000080: 65 0d 0a 00 00 00 00 00 e.......
1682
1683For more information, see http://volatility-labs.blogspot.com/2012/10/solving-grrcon-network-forensics.html
1684
16853. Create one or more ADS files on your system. Acquire memory and run mftparser. Does it find the ADS associations?
1686
1687The correct answer is: N/A
1688
16894. Move a file on your machine to the recycle bin. Then analyze your activity with mftparser. Can you find evidence of the "deleted" file? Parse the $I file and recover the original full path.
1690
1691The correct answer is: N/A
1692
16935. Extract all files from one or more memory dumps. Run the UNIX "file" command against the output directory. What types of files did you recover?
1694
1695You can do this like:
1696
1697$ mkdir output
1698$ python vol.py -f MEMORY.DMP --profile=PROFILE -D output dumpfiles
1699$ file output/*
1700
17016. Perform the following steps:
1702
1703 A) Install Truecrypt on your machine
1704 B) Create a virtual file-based container
1705 C) Mount the container with or without cached passwords
1706 D) Store some files within the encrypted container
1707 E) Acquire a memory dump from your system
1708 F) Use the truecryptpassphrase, truecryptsummary, and truecryptmaster plugins to investigate the activity
1709
1710The correct answer is: N/A
1711
17127. Assuming your Truecrypt file was using NTFS, locate the $Mft file and extract it with dumpfiles. Parse it offline to determine the names of other files within the encrypted volume.
1713
1714You can find the $Mft entries with filescan or from the output of truecryptsummary.
1715
1716$ python vol.py -f MEMORY.DMP --profile=PROFILE filescan | grep Mft
1717
1718Then pass the physical offset as -Q to dumpfiles.
1719
1720----------------------------------------------------------------------
1721Chapter 17: Event Reconstruction
1722----------------------------------------------------------------------
1723
17241. Extract strings from one or more of your memory dumps.
1725
1726For example:
1727
1728$ strings -a -td MEMORY.DMP > strings.txt
1729$ strings -a -el -td MEMORY.DMP >> strings.txt
1730
17312. Translate the strings with Volatility.
1732
1733For example:
1734
1735$ python vol.py -f MEMORY.DMP --profile=PROFILE strings -s strings.txt > translated.txt
1736
17373. Search your translated strings file for activity related to file execution (prefetch), C2 hostnames (this will depend on the malware you install prior to dumping memory), etc.
1738
1739The correct answer is: N/A
1740
17414. Are there any related strings immediately above or below the potentially interesting strings you found in Step 3?
1742
1743The correct answer is: N/A (hint: use grep -C, grep -A, or grep -B)
1744
17455. Isolate the "FREE MEMORY" strings from the translated file. What percentage of the total strings are found in free/deallocated memory?
1746
1747The correct answer is: N/A
1748
17496. What strings are shared between multiple processes? Can you map them back to specific DLLs in those processes?
1750
1751The correct answer is: N/A (hint: the shared strings will have multiple process IDs in the translated.txt file)
1752
17537. Run the cmdscan and consoles plugins against all samples provided with the book as well as your own memory images. Do you find any useful information?
1754
1755The correct answer is: N/A
1756
1757----------------------------------------------------------------------
1758Chapter 18: Timelining
1759----------------------------------------------------------------------
1760
17611. Most timelines found in Windows memory dumps are in local time.
1762
1763 True or False?
1764
1765The correct answer is: False (they are in UTC)
1766
17672. Which command-line option helps create timelines in a format that's compatible with disk forensics tools and other common utilities?
1768
1769 A) --output=timeline
1770 B) --output=csv
1771 C) --output=body
1772 D) --output=bodyfile
1773
1774The correct answer is: C
1775
17763. Create a timeline from sample001.bin.
1777
1778 A) Run timeliner
1779 B) Run shellbags
1780 C) Run mftparser
1781 D) Extract the registry hive files and process them with python-registry
1782 E) Combine the output into one large timeline
1783 F) Sort the timeline with mactime
1784
1785The correct answer is: N/A
1786
17874. Analyze the timeline you created in Question 3 for signs of infection. What was the initial infection vector and when did it occur? What events followed?
1788
1789See the answer to the next question.
1790
17915. Create a timeline for sample005.bin. Can you find any relation with sample001.bin?
1792
1793Both sample001.bin and sample005.bin are memory images produced by Jack Crook for his forensic challenge. The sample001.bin is the "ENG" machine and sample005.bin is "IIS." Now read through Chapter 18's analysis of the involved systems and see if they confirm your own suspicions.
1794
1795---------------------------------------------------------------
1796Chapter 19: Linux Memory Acquisition
1797---------------------------------------------------------------
1798
17991. Why is /dev/mem no longer usable for memory acquisition?
1800
1801 A) It is disabled on modern distributions
1802 B) It only supports acquisition of 1MB of memory
1803 C) It only supports acquisition of 2GB of memory
1804 D) It is not readable by userland programs
1805
1806The correct answer is: B
1807
18082. Why is /dev/kmem no longer usable for memory acquisition?
1809
1810 A) It is disabled on modern distributions
1811 B) It only supports acquisition of 1MB of memory
1812 C) It only supports acquisition of 2GB of memory
1813 D) It is not readable by userland programs
1814
1815The correct answer is: A
1816
18173. What is one advantage that LiME has over fmem?
1818
1819 A) It runs from userland
1820 B) It can be compiled once and work on any supported system
1821 C) It is open source
1822 D) It automates the acquisition process
1823
1824The correct answer is: D
1825
18264. On which of the following system(s) would /proc/kcore be usable?
1827
1828 A) 32-bit Redhat running kernel version 2.6.32
1829 B) 64-bit Ubuntu running kernel version 2.6.24
1830 C) 32-bit Mandriva running kernel version 2.6.21
1831 D) 64-bit SuSe running kernel version 3.12
1832
1833The correct answer is: B, D
1834
18355. In order to create a Volatility Linux profile you must compile the profile on a system running the same kernel version and OS as you want to analyze.
1836
1837 True/False?
1838
1839The correct answer is: False (you can cross-compile)
1840
18416. Perform the following steps:
1842
1843 A) Install the latest version of Ubuntu within a virtual machine or on real hardware
1844 B) Compile LiME for the system and create a Volatility profile. This will require installing the compiler tools and the kernel headers
1845 C) Use LiME to acquire memory and then analyze it with the linux_pslist plugin using the profile you created
1846
1847The correct answer is: N/A
1848
1849---------------------------------------------------------------
1850Chapter 20: Linux Operating System
1851---------------------------------------------------------------
1852
18531. Which of the following dictate the sections of an ELF file load into memory at runtime?
1854
1855 A) The ELF header
1856 B) The section headers
1857 C) The program headers
1858 D) The section symbol table
1859
1860The correct answer is: C
1861
18622. How does Volatility's Linux support find the initial DTB?
1863
1864 A) Scanning physical memory looking for an allocation signature
1865 B) Utilizing Linux's identity mapping of kernel code and data
1866 C) Finding the init process and then finding its page table value
1867 D) Walking the list of kernel modules until the kernel is found and then finding its page table value
1868
1869The correct answer is: B
1870
18713. The proc file system is correctly acquired when performing disk imaging, such as through the dd command.
1872
1873 True/False?
1874
1875The correct answer is: False (/proc is a memory-only file system)
1876
18774. The /proc/1/ directory corresponds to which type of object?
1878
1879 A) Process
1880 B) Network Connection
1881 C) Opened File Handles
1882 D) Kernel Module
1883
1884The correct answer is: A
1885
18865. Analyze /bin/ls from the Ubuntu installation that you created in the previous chapter. Using readelf -WS and nm, answer the following questions:
1887
1888 A) How many sections does the binary have?
1889 B) How many symbols does the binary contain?
1890 C) What is the virtual address of the .text section?
1891
1892The correct answer can be determined by using nm (or readelf -Ws) to read the file's symbols and readelf -WS to read the sections. For example, in the following output you can see each section and where it is loaded:
1893
1894$ readelf -WS /bin/ls
1895There are 28 section headers, starting at offset 0x1b670:
1896
1897Section Headers:
1898 [Nr] Name Type Address Off Size ES Flg Lk Inf Al
1899 [ 0] NULL 0000000000000000 000000 000000 00 0 0 0
1900 [ 1] .interp PROGBITS 0000000000400238 000238 00001c 00 A 0 0 1
1901 [ 2] .note.ABI-tag NOTE 0000000000400254 000254 000020 00 A 0 0 4
1902 [ 3] .note.gnu.build-id NOTE 0000000000400274 000274 000024 00 A 0 0 4
1903 [ 4] .hash HASH 0000000000400298 000298 000370 04 A 6 0 8
1904 [ 5] .gnu.hash GNU_HASH 0000000000400608 000608 000060 00 A 6 0 8
1905 [ 6] .dynsym DYNSYM 0000000000400668 000668 000b58 18 A 7 1 8
1906 [ 7] .dynstr STRTAB 00000000004011c0 0011c0 000568 00 A 0 0 1
1907 [ 8] .gnu.version VERSYM 0000000000401728 001728 0000f2 02 A 6 0 2
1908 [ 9] .gnu.version_r VERNEED 0000000000401820 001820 0000a0 00 A 7 3 8
1909 [10] .rela.dyn RELA 00000000004018c0 0018c0 000078 18 A 6 0 8
1910 [11] .rela.plt RELA 0000000000401938 001938 0009d8 18 A 6 13 8
1911 [12] .init PROGBITS 0000000000402310 002310 00000e 00 AX 0 0 4
1912 [13] .plt PROGBITS 0000000000402320 002320 0006a0 10 AX 0 0 16
1913 [14] .text PROGBITS 00000000004029c0 0029c0 01022c 00 AX 0 0 16
1914 [15] .fini PROGBITS 0000000000412bec 012bec 000009 00 AX 0 0 4
1915<snip>
1916
1917---------------------------------------------------------------
1918Chapter 21: Processes and Process Memory
1919---------------------------------------------------------------
1920
19211. The linux_pstree plugin is helpful in which situation?
1922
1923 A) Finding hidden processes
1924 B) Determining when processes exited
1925 C) Mapping processes to network connections
1926 D) Determining the child/parent relationship between processes
1927
1928The correct answer is: D
1929
19302. The name of the process reported by linux_pslist is susceptible to userland manipulation.
1931
1932 True/False?
1933
1934The correct answer is: False (the name is stored in kernel memory)
1935
19363. The name of the process reported by linux_psaux is susceptible to userland manipulation.
1937
1938 True/False?
1939
1940The correct answer is: True (this value comes from the process' address space)
1941
19424. What does the PATH environment variable specify?
1943
1944 A) The list of directories writable by the user
1945 B) The list of directories to search for applications
1946 C) The list of directories to search for shared libraries
1947 D) The list of directories storing user configuration files
1948
1949The correct answer is: B
1950
19515. When using default settings, which of these appear in bash's data structures in memory, but not on disk?
1952
1953 A) The order in which commands were executed
1954 B) The time when commands were executed
1955 C) The user who executed commands
1956 D) The directory commands were executed from
1957
1958The correct answer is: B
1959
19606. For the remaining questions of this chapter, analyze linux-sample-1.bin using the provided profile.
1961
1962 A) What is the ID of the user that read the passwd and shadow file?
1963 B) Did this user log in locally or over SSH?
1964 C) Which parameters were passed to the command when first elevating privileges (hint: check the environment of the relevant process)?
1965 D) What is the user ID of the user logged into the desktop locally?
1966 E) Which network services are running on the system?
1967
1968Answers:
1969
1970If you run the linux_bash plugin you see that a PID of 8503 had read both files:
1971
1972$ python vol.py -f linux-sample-1.bin --profile=Linuxbookx64 linux_bash
1973Volatility Foundation Volatility Framework 2.4
1974Pid Name Command Time Command
1975-------- -------------------- ------------------------------ -------
1976<snip>
1977 8503 bash 2014-06-24 13:00:12 UTC+0000 cat /etc/passwd
1978 8503 bash 2014-06-24 13:00:17 UTC+0000 cat /etc/group
1979
1980If you look up that process with pslist you can see that the user ID (UID) is 1001:
1981
1982$ python vol.py -f linux-sample-1.bin --profile=Linuxbookx64 linux_pslist -p 8503
1983Volatility Foundation Volatility Framework 2.4 (Beta)
1984Offset Name Pid Uid Gid DTB Start Time
1985----------------- ----- --- --- --- --------- ----------
19860xffff88001ac9c740 bash 8503 1001 1001 0x1ee6000 2014-06-24 12:58:55 UTC+0000
1987
1988linux_pstree shows that sshd is the parent of the bash process with PID 8503:
1989
1990$ python vol.py -f linux-sample-1.bin --profile=Linuxbookx64 linux_pstree
1991<snip>
1992.sshd 3373 0
1993..sshd 8497 0
1994...sshd 8502 1001
1995....bash 8503 1001
1996<snip>
1997
1998linux_bash shows the use of ‘su' a few seconds before the shadow file is read:
1999
2000$ python vol.py -f linux-sample-1.bin --profile=Linuxbookx64 linux_pstree
2001<snip>
2002 8503 bash 2014-06-24 13:00:02 UTC+0000 su
2003
2004The user ID of the local user is 1000 as shown by linux_pslinux.
2005
2006Apache2, smbd, exim, and dovecot are all actively listening on the network.
2007
2008---------------------------------------------------------------
2009Chapter 22: Networking Artifacts
2010---------------------------------------------------------------
2011
20121. Activity related to UNIX sockets would appear in a program such as Wireshark running on the local machine.
2013
2014 True/False
2015
2016The correct answer is: False (Wireshark does not analyze UNIX sockets)
2017
20182. Raw sockets are used only for malicious purposes.
2019
2020 True/False
2021
2022The correct answer is: False
2023
20243. Why is the ARP cache useful for forensics?
2025
2026 A) It contains remote IP addresses of attackers
2027 B) It contains remote IP addresses used for data exfiltration
2028 C) It contains information about local IP addresses contacted during lateral movement
2029 D) It contains information about local IP addresses assigned to printers
2030
2031The correct answer is: C
2032
20334. Which networking artifact was removed from subsequent versions of the Linux kernel?
2034
2035 A) Packet queues
2036 B) Aliased interfaces
2037 C) ARP cache
2038 D) Routing cache
2039
2040The correct answer is: D
2041
20425. For the remaining questions of this chapter, analyze linux-sample-2.bin using the provided profile.
2043
2044 A) Which web browser was used by the user of the system?
2045 B) What was the PID of the main browser in use?
2046 C) Which IP addresses were contacted using HTTPS?
2047 D) What type of browsing activity does the route cache show?
2048 E) Which processes are listening for connections?
2049 F) How many network interfaces are active on the system?
2050 G) Are any of the interfaces in promiscuous mode?
2051
2052Answers:
2053
2054linux_pslist shows that the iceweaseal browser is running as PID 8700.
2055
2056To determine IP addresses contacted, you can filter linux_netstat with the –p option for 8700 and grep for port 443:
2057
2058$ python vol.py -f linux-sample-2.bin --profile=Linuxbookx64 linux_netstat -p 8700 | grep 443
2059Volatility Foundation Volatility Framework 2.4 (Beta)
2060TCP 192.168.201.161:51499 74.125.228.36:443 ESTABLISHED iceweasel/8700
2061TCP 192.168.201.161:58610 206.190.56.190:443 ESTABLISHED iceweasel/8700
2062TCP 192.168.201.161:58615 206.190.56.190:443 ESTABLISHED iceweasel/8700
2063TCP 192.168.201.161:38091 74.125.228.59:443 ESTABLISHED iceweasel/8700
2064TCP 192.168.201.161:33011 93.184.216.146:443 ESTABLISHED iceweasel/8700
2065TCP 192.168.201.161:41442 91.190.218.18:443 ESTABLISHED iceweasel/8700
2066TCP 192.168.201.161:47616 173.252.112.23:443 ESTABLISHED iceweasel/8700
2067TCP 192.168.201.161:57400 74.125.228.60:443 ESTABLISHED iceweasel/8700
2068TCP 192.168.201.161:41488 23.59.244.47:443 ESTABLISHED iceweasel/8700
2069TCP 192.168.201.161:38180 168.143.241.160:443 ESTABLISHED iceweasel/8700
2070TCP 192.168.201.161:38181 168.143.241.160:443 ESTABLISHED iceweasel/8700
2071TCP 192.168.201.161:39245 74.125.29.95:443 ESTABLISHED iceweasel/8700
2072TCP 192.168.201.161:33851 74.125.228.42:443 ESTABLISHED iceweasel/8700
2073
2074The linux_route_cache plugin with the –R option shows connections to several websites.
2075
2076To determine listening processes, use linux_netstat and grep for LISTEN.
2077
2078linux_ifconfig shows two active interfaces and that neither are in promiscuous mode:
2079
2080$ python vol.py -f linux-sample-2.bin --profile=Linuxbookx64 linux_ifconfig
2081Volatility Foundation Volatility Framework 2.4
2082Interface IP Address MAC Address Promiscuous Mode
2083---------------- -------------------- ------------------ ---------------
2084lo 127.0.0.1 00:00:00:00:00:00 False
2085eth0 192.168.201.161 00:0c:29:8f:ed:ca False
2086
2087---------------------------------------------------------------
2088Chapter 23: Kernel Memory Artifacts
2089---------------------------------------------------------------
2090
20911. What type of information would NOT be found in the kernel debug buffer?
2092
2093 A) User logins
2094 B) Removable device usage
2095 C) Wireless network activity
2096 D) Listings of attached hardware devices
2097
2098The correct answer is: A
2099
21002. The linux_lsmod plugin finds kernel modules through scanning physical memory.
2101
2102 True/False?
2103
2104The correct answer is: False (it walks the linked list)
2105
21063. The Linux kernel uses a 2GB / 2GB split of virtual memory on 32-bit systems.
2107
2108 True/False
2109
2110The correct answer is: False (it uses 3GB / 1GB)
2111
21124. What is NOT true of kernel modules extracted with linux_moddump?
2113
2114 A) They can be scanned with AV and Yara signatures
2115 B) They can be reverse engineered
2116 C) They can be reloaded on the live system
2117 D) They will not match the hash of the original LKM from disk
2118
2119The correct answer is: C
2120
21215. module_addr_min and module_addr_max specify the beginning and ending address of which data in kernel memory?
2122
2123 A) The kernel executable
2124 B) The last kernel module to load
2125 C) The memory range occupied by all kernel modules
2126 D) The last kernel module to unload
2127
2128The correct answer is: C
2129
21306. For the remaining questions of this chapter, analyze linux-sample-3.bin using the provided profile.
2131
2132 A) At what address is the lime kernel module loaded? Use this address to dump the kernel module from memory
2133 B) How many sections does the module have?
2134 C) Where is the .text section loaded in memory?
2135 D) Which parameter(s) were passed to LiME to dump memory?
2136 E) Which physical addresses does RAM occupy?
2137 F) Did LiME acquire only these regions or others as well?
2138
2139linux_lsmod and linux_moddump can be used to acquire the module from memory:
2140
2141$ python vol.py -f linux-sample-3.bin --profile=Linuxbookx64 linux_lsmod | grep lime
2142Volatility Foundation Volatility Framework 2.4
2143ffffffffa03b2010 lime 17991
2144
2145$ python vol.py -f linux-sample-3.bin --profile=Linuxbookx64 linux_moddump -b 0xffffffffa03b2010 -D .
2146Volatility Foundation Volatility Framework 2.4
2147Wrote 2053656 bytes to lime.0xffffffffa03b2010.lkm
2148
2149You can find the address of the .text section using readelf on the extracted module or with the –T parameter to linux_lsmod. The –P flag can be used to recover the parameters.
2150
2151The linux_iomem plugin lists the regions of physical memory. You can verify that LiME only acquired RAM regions by comparing linux_iomem with the output of the limeinfo plugin.
2152
2153---------------------------------------------------------------
2154Chapter 24: File Systems in Memory
2155---------------------------------------------------------------
2156
21571. What effect does the noatime mount option have on forensics?
2158
2159 A) Access times of directories are not updated
2160 B) Access times of files are not updated
2161 C) Access times of files and directories are not updated
2162 D) Access times of files are updated only when accessed by the owner
2163
2164The correct answer is: C
2165
21662. When replicating file systems from memory, which MAC time is not replicated?
2167
2168 A) Modified
2169 B) Accessed
2170 C) Created
2171
2172The correct answer is: C
2173
21743. Which of the following file systems is not stored on disk?
2175
2176 A) tmpfs
2177 B) ext3
2178 C) xfs
2179 D) jfs
2180
2181The correct answer is: A
2182
21834. Which of the following directories is often used by attackers to store data that does not need to persist across reboots?
2184
2185 A) /usr/tmp
2186 B) /dev/mm
2187 C) /tmp
2188 D) /var/runlib
2189
2190The correct answer is: C
2191
21925. If one page of a file is accessed by an application, then the entire file is read into the file cache
2193
2194 True/False?
2195
2196The correct answer is: False (only the required portion and potentially a small read-ahead chunk)
2197
21986. For the remaining questions of this chapter, analyze linux-sample-3.bin using the provided profile.
2199
2200 A) Recover the cookies.sqlite file of the vol user. Which websites stored cookies on this user's system?
2201 B) How many entries are in /etc/hosts?
2202 C) What type of file is /home/vol/.cache/mozilla/firefox/sren9std.default/Cache/8/10/4B0E7d01?
2203
2204Answers:
2205
2206These files can all be recovered with linux_find_file or linux_recover_filesystem. An sqlite viewer can view the cookie database, a text editor can view the hosts file, and the file command reveals that the cache file is a picture.
2207
2208---------------------------------------------------------------
2209Chapter 25: Userland Rootkits
2210---------------------------------------------------------------
2211
22121. Which of the following operations is not directly supported by ptrace?
2213
2214 A) Attaching to a running process
2215 B) Reading from a remote process' memory
2216 C) Creating a thread in a remote process
2217 D) Setting the general purpose registers of a remote process
2218
2219The correct answer is: C
2220
22212. How are LD_PRELOAD-based rootkits detected?
2222
2223 A) By checking for inline hooks
2224 B) By hashing files on disk and comparing the hash to the in-memory version
2225 C) By checking for GOT overwrites
2226 D) By comparing string comparison operations
2227
2228The correct answer is: C
2229
22303. GOT overwrites are equivalent to which type of hook on Windows?
2231
2232 A) SSDT hooks
2233 B) IAT/EAT hooks
2234 C) Callback hooks
2235 D) IDT hooks
2236
2237The correct answer is: B
2238
22394. For stability reasons, which set of instructions is generally overwritten by inline hooks?
2240
2241 A) The first few instructions of a function
2242 B) The last few instructions of a function
2243 C) The instructions after the first CALL instruction
2244 D) The instructions after the first CMP instruction
2245
2246The correct answer is: A
2247
22485. Detection of which type of hook requires the original application binary or shared library?
2249
2250 A) Inline hook
2251 B) GOT overwrite
2252 C) Process hollowing
2253 D) Function pointer overwrite
2254
2255The correct answer is: C
2256
22576. For the following questions analyze linux-sample-4.bin using the provided profile.
2258
2259 A) Which processes are victim of an LD_PRELOAD attack?
2260 B) Which user is running the infected processes?
2261 C) What is the full path to the injected library?
2262 D) How does the library get injected into each process of the user?
2263 E) Which function(s) are the malicious library hooking?
2264 F) What is the path to the logfile that the library stores stolen data to disk in?
2265
2266Answer:
2267
2268linux_plthook can find processes infected with LD_PRELOAD. In particular it finds that the pico process (/bin/nano) has its fwrite function hooked by a library /home/mark/.bashinit. This library's place in the file system and name are both very suspicious.
2269
2270The library gets loaded into each process of the mark user through hijacking of the .bashrc file.
2271The path to the logfile can be found by using linux_lsof on the infected process.
2272
22737. For the following questions analyze linux-sample-5.bin using the provided profile.
2274
2275 A) Which process is inline hooked?
2276 B) Which function is inline hooked?
2277 C) What is the purpose of the inline hook?
2278 D) What is the name of the library performing the hook?
2279
2280Answer:
2281
2282linux_apihooks shows two results for the bash process with PID 3619:
2283
2284$ python vol.py -f linux-sample-5.bin --profile=Linuxbookx64 linux_apihooks
2285Volatility Foundation Volatility Framework 2.4
2286Pid Name Hook VMA Hook Symbol Hooked Address Type Hook Address Hook Library
2287------- ---------------- ---------------------------------------- ------------------------ ------------------ ----- ------------------ ------------
2288 3619 bash /lib/x86_64-linux-gnu/libc-2.13.so time 0x00007f4429b45950 CALL 0x0000000000000000 <Unknown mapping>
2289 3619 bash /lib/x86_64-linux-gnu/libc-2.13.so open 0x00007f4429b77f00 JMP 0x00007f44290708b0 /run/shm/b
2290
2291The first for the time function is a false positive, but the second shows that the open function is being redirected to a library named b that is stored within /run/shm. This is very suspicious.
2292
2293---------------------------------------------------------------
2294Chapter 26: Kernel Mode Rootkits
2295---------------------------------------------------------------
2296
22971. Legitimate system call handlers can be implemented in kernel modules.
2298
2299 True/False?
2300
2301The correct answer is: False
2302
23032. Which of the following members of tcp4_seq_info is commonly hooked in order to hide a rootkit's network connections?
2304
2305 A) start
2306 B) stop
2307 C) next
2308 D) show
2309
2310The correct answer is: D
2311
23123. The NF_REPEAT Netfilter option is often used by rootkits to hide network connections from other kernel components and userland packet sniffers.
2313
2314 True/False?
2315
2316The correct answer is: False (they often use NF_STOLEN)
2317
23184. How does Average Coder hide logged-in users from the system?
2319
2320 A) Hooking the write operation of /proc/buddyinfo
2321 B) Hooking the read operation of /var/run/utmp
2322 C) Hooking the read directory operation of /var/run
2323 D) Hooking the open operation of /usr/bin/who
2324
2325The correct answer is: B
2326
23275. Which userland-accessible source on a live system can find kernel modules hidden from the global list of modules?
2328
2329 A) The IO_GET_MODULES I/O control request
2330 B) The /sys/module directory
2331 C) The /proc/modules file
2332 D) The get_modules system call
2333
2334The correct answer is: B
2335
23366. For the following questions analyze linux-sample-6.bin using the provided profile.
2337
2338 A) Where is the malicious kernel module loaded?
2339 B) Which system calls are hooked?
2340 C) Which capabilities can the hooks give to the rootkit?
2341 D) What type of hooks are placed in the file system?
2342 E) Are there hooks in the network stack?
2343
2344Answers:
2345
2346The hidden module can be found with linux_check_modules:
2347
2348$ python vol.py -f linux-sample-6.bin --profile=Linuxbookx64 linux_check_modules
2349Volatility Foundation Volatility Framework 2.4
2350 Module Address Module Name
2351------------------ ------------------------
23520xffffffffa04280a0 ipsecs_kbeast_v1
2353
2354linux_check_syscall can be used to find the hooked indexes:
2355
2356python vol.py -f /mnt/hgfs/Desktop/linux-sample-6.bin --profile=Linuxbookx64 linux_check_syscall
2357Volatility Foundation Volatility Framework 2.4
2358Table Name Index System Call Handler Address Symbol
2359---------- ----- ------------------------ ------------------ ------------------------------------------------------------
236064bit 0 0xffffffffa04259b6 HOOKED: ipsecs_kbeast_v1/h4x_read
236164bit 1 0xffffffffa04250e7 HOOKED: ipsecs_kbeast_v1/h4x_write
236264bit 2 0xffffffffa042548f HOOKED: ipsecs_kbeast_v1/h4x_open
2363<snip>
2364
2365linux_check_fop and linux_check_afinfo can be used to determine the file system and network stack hooks.
2366
2367$ python vol.py -f linux-sample-6.bin --profile=Linuxbookx64 linux_check_afinfo
2368Volatility Foundation Volatility Framework 2.4
2369Symbol Name Member Address
2370------------------------------------------ ------------------------------ ------------------
2371tcp4_seq_afinfo show 0xffffffffa04255db
2372
2373---------------------------------------------------------------
2374Chapter 27: Case Study: Phalanx 2
2375---------------------------------------------------------------
2376
23771. How does P2 hide processes?
2378
2379 A) IOCTL handler hooks
2380 B) System call hooks
2381 C) Direct Kernel Object Manipulation (DKOM)
2382 D) Inline hooks in the libc mapped into each process
2383
2384The correct answer is: B
2385
23862. What was unusual about P2's network connections?
2387
2388 A) P2 connected multiple times to a hardcoded remote IP addresses
2389 B) P2 connected to itself over the network
2390 C) P2 connected performed DNS resolution using Godaddy's DNS servers
2391 D) The connections occurred only over IPv6
2392
2393The correct answer is: B
2394
23953. P2 performs the majority of its work through a loadable kernel module.
2396
2397 True/False?
2398
2399The correct answer is: False (most occurs in user mode through /dev/mem)
2400
24014. Which directory does P2 use to mark its presence on a system?
2402
2403 A) /tmp
2404 B) /var/run
2405 C) /dev/shm
2406 D) /etc
2407
2408The correct answer is: C
2409
24105. P2 re-executes itself upon startup so that it will not appear in the process list.
2411
2412 True/False?
2413
2414The correct answer is: False (it re-executes to break from ptrace)
2415
2416----------------------------------------------------------------------
2417Chapter 28: Mac Acquisition and Internals
2418----------------------------------------------------------------------
2419
24201. On Mac systems, processes run in the Mach layer and the kernel runs in the BSD layer.
2421
2422 True/False?
2423
2424The correct answer is: False (the kernel does not run in the BSD layer)
2425
24262. Why does Volatility need to account for the Mac kernel's address space layout randomization?
2427
2428 A) Userland libraries will be mapped into different offsets than reported by the virtual memory subsystem structures
2429 B) Addresses in the profile will not correspond to where the data structures are mapped in the memory capture
2430 C) Scanning for data structures requires smarter algorithms when ASLR is in use
2431 D) Volatility does not need to account for it
2432
2433The correct answer is: B
2434
24353. Physical memory acquisition on Mac systems can be accomplished using built-in operating system facilities.
2436
2437 True/False?
2438
2439The correct answer is: False (there is no supported built-in API for acquisition)
2440
24414. Mac Memory Reader supports capture to the ELF format.
2442
2443 True/False?
2444
2445The correct answer is: False (it supports padded, non-padded, and mach-o)
2446
24475. Which of the following is required to build a Mac Volatility profile?
2448
2449 A) The kernel header files
2450 B) C/C++ Compiler tools
2451 C) Mac ports
2452 D) The kernel debug kit
2453
2454The correct answer is: D
2455
24566. If you have access to an OS X system, then build a Volatility profile for Mac 10.9.3.
2457
2458----------------------------------------------------------------------
2459Chapter 29: Mac Memory Overview
2460----------------------------------------------------------------------
2461
24621. What is the name of the process that spawns the initial launchd process?
2463
2464 A) kernel_task
2465 B) swapper
2466 C) init
2467 D) SYSTEM
2468
2469The correct answer is: A
2470
24712. When the dyld cache is in use, mac_proc_maps will properly list all shared libraries.
2472
2473 True/False?
2474
2475The correct answer is: False (you must use mac_dydl_maps)
2476
24773. Mac tracks kernel modules only through a global list of modules.
2478
2479 True/False?
2480
2481The correct answer is: False
2482
24834. Which command lists active network connections along with their owning process on a live Mac system?
2484
2485 A) netstat –an
2486 B) netstat –pan
2487 C) lsof –i
2488 D) lsof -p
2489
2490The correct answer is: C
2491
24925. To answer the following questions, analyze mac-sample-1.bin with the provided 10.9.3 profile.
2493
2494 A) Which user ID is the vim process run by?
2495 B) Is the user logged in locally or remotely?
2496 C) What is the path to the file being edited in vim?
2497 D) What is the full path to vim on the local system?
2498 E) What is the load address of libmacho.dylib inside the running vim process?
2499 F) What text was being typed in vim at the time of acquisition?
2500 G) Which websites were being accessed around the time of acquisition?
2501
2502Answer:
2503
2504mac_pslist shows that vim is running as user ID 501. mac_pstree shows that vim is spawned by Terminal on the local system. mac_proc_maps can be used to find the full path to vim:
2505
2506$ python vol.py -f mac-sample-1.bin --profile=MacMavericks_10_9_3_AMDx64 mac_proc_maps -p 757
2507Volatility Foundation Volatility Framework 2.4 (Beta)
2508757 vim 0x108042000 0x108188000 r-x Macintosh HD/usr/bin/vim
2509
2510mac_dyld_maps can be used to list the library address.
2511
2512The text being typed into vim can be recovered through analysis of the vim heap and also the .swp file created by vim for the file.
2513
2514mac_route can be used to determine which IP addresses the system was connected to.
2515
2516----------------------------------------------------------------------
2517Chapter 30: Malicious Code and Rootkits
2518----------------------------------------------------------------------
2519
25201. DYLD_INSERT_LIBRARIES is similar to which concept of Linux?
2521
2522 A) ptrace
2523 B) MAP_LIBRARY_ON_START
2524 C) LD_PRELOAD
2525 D) Inline hooking
2526
2527The correct answer is: C
2528
25292. sysctl provides an interface for the kernel to request actions from userland processes.
2530
2531 True/False?
2532
2533The correct answer is: True
2534
25353. Which of the following is not a standard TrustedBSD policy module?
2536
2537 A) TMSafetyNet
2538 B) Sandbox
2539 C) Quarantine
2540 D) AppleEvents
2541
2542The correct answer is: D
2543
25444. Which feature of Mac is similar to Windows run keys?
2545
2546 A) Launch Agents
2547 B) Spotlight
2548 C) Service Indexes
2549 D) Application Preloads
2550
2551The correct answer is: A
2552
25535. The NSCreateObjectFileImageFromMemory API facilitates which of the following anti-forensics techniques?
2554
2555 A) Hiding a library from a process' list of libraries
2556 B) Process hollowing
2557 C) API hooking
2558 D) Reconstructed library injection
2559
2560The correct answer is: A
2561
25626. To answer the following questions, analyze mac-sample-2.bin with the provided 10.9.3 profile. There is a kernel rootkit installed that you must find and track.
2563
2564 A) What is the name of the kernel rootkit?
2565 B) How does it hook the system?
2566 C) What is the address of the kernel module in memory?
2567 D) Extract the kernel module
2568 E) What is the MD5 hash of the extracted module?
2569
2570The rootkit is logKext. It can be found through mac_lsmod and mac_notifiers.
2571
2572----------------------------------------------------------------------
2573Chapter 31: Tracking User Activity
2574----------------------------------------------------------------------
2575
25761. The Mac default login keychain only holds the password of the user.
2577
2578 True/False?
2579
2580The correct answer is: False (it stores a variety of other passwords and credentials)
2581
25822. Each password inside a keychain is encrypted with a different key and must be opened separately.
2583
2584 True/False?
2585
2586The correct answer is: False (they're all encrypted with the same key)
2587
25883. Which of the following plugins enables rapid development of new application-specific analysis plugins?
2589
2590 A) mac_pslist
2591 B) mac_proc_maps
2592 C) mac_yarascan
2593 D) mac_lsof
2594
2595The correct answer is: C
2596
25974. How does Volatility recover clear-text OTR messages?
2598
2599 A) It finds remnant session keys then attempts to decrypt all recovered encrypted messages
2600 B) It finds the clear-text messages displayed to the user through the chat window
2601 C) It finds the data structures that hold clear-text messages after they are sent on the wire
2602 D) It finds encryption keys in memory then applies them to encrypted messages stored in PCAP files
2603
2604The correct answer is: B
2605
26065. To answer the following questions analyze mac-sample-3.bin using the provided 10.9.3 profile. In this sample a user is logged into an email account using the Apple Mail client.
2607
2608 A) What is the user account configured for the Apple Mail client to use?
2609 B) Which account did the person send an email to and receive a reply from?
2610 C) What time was the email sent?
2611 D) What is (was) the password to the Gmail account?
2612 E) How many emails did the user send?
2613
2614These questions can be answered using mac_yarascan and searching for Gmail and email related activity.
2615
2616The email account is iaminakeychain@gmail.com. The conversation occurred with atcuno@gmail.com.
2617Entire message contents can be found through examination of memory with memdump or yarascan on PID 258 (the mail client).
2618
2619The orignal password to the account can be found by looking for the Passwd HTTPS POST parameter:
2620
2621$ python vol.py -f mac-sample-3.bin --profile=MacMavericks_10_9_3_AMDx64 mac_yarascan -p 258 -Y "&Pass"
2622Volatility Foundation Volatility Framework 2.4
2623Task: Mail pid 258 rule r1 addr 0x10a06b9ad
26240x000000010a06b9ad 26 50 61 73 73 77 64 3d 62 72 65 61 6b 6d 65 64 &Passwd=breakmed
26250x000000010a06b9bd 6f 77 6e 34 35 36 26 73 65 72 76 69 63 65 3d 6d own456&service=m
2626<snip>
2627
26286. To answer the following questions analyze mac-sample-4.bin using the provided 10.9.3 profile.
2629
2630 A) Which messages were being written in the Notes application?
2631 B) Create a plugin that can automatically find messages within the address space of the TextEdit application. Use this plugin to recover the messages being typed by the user.
2632
2633Answer: The messages being written into the Notes application can be recovered using the mac_notesapp plugin.
2634---
2635Day Milovich,,