今天實作經典的 Memory Forensics 工具 Volatility 2.6。
Volatility 是一套開源的記憶體取證分析工具,使用 python 編寫成,以命令提示字元操作,可以從 Memory Dump 中解析出 Process、Network Connection、Registry、Command History 等資訊。
簡單來說,前幾天比較像是在問:
Memory 裡留下了哪些資料?
今天則開始問:
Capture Memory 的那一刻,系統到底在執行什麼?連到哪裡?又留下哪些系統資訊?
Volatility 2.6 已經是比較舊的版本,對較新的 Windows 版本支援有限;後面也會再使用 Volatility 3。今天先從 2.6 開始,因為很多經典的 Memory Forensics 教材與舊 Memory Image 都還是使用這個版本。
先在 cmd 中 ls Volatility2.6 資料夾
包含 Suggested profile、Image time 等等
要注意這裡的 time 都是 UTC+0000
Suggested profile 有可能會用到
volatility_2.6_win64_standalone.exe -f [映像檔] imageinfo

有機會可以找出 rootkits 隱藏的連線狀態
如果 Suggested profile 是 WinXP 可以用 connscan ,其他用 netscan
有幾點我們可以注意的 :
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] connscan

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] netscan

可以根據異常的 PID 往下追查
TimeStamp 很重要,是 Report 的必要元素
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] psscan

volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] psxview
True : 指令、參數底下都會show出的結果,不用優先看
False : 特定指令看不到,可以先觀察差異欄位,進行反鑑識
像是此例子要先針對 cmd.exe 進行進一步追查,雖然他是 cmd.exe 但也有可能是惡意程式偽裝

pstree 會列出樹狀結構
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] pstree
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] pslist
SAM = 帳號對應的 LM/NTLM hash
system = SYSKEY(用來再加密 SAM)
只要 Heartbleed 漏洞沒修補,攻擊者就能一直讀取記憶體內容,所以只把密碼改強也沒用。
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] hivelist

查看 Windows 的 NTLM hash,可以進一步用 John the Ripper 破解出 Password
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] hashdump -y [key 的 offset] -s [hash 的 offset]

cmd 不會列出 Timstamp,只會有執行順序
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] cmdscan

hiberfil.sys : Windows 休眠時儲存的壓縮、重映後的 RAM 檔案
若要分析 hiberfil.sys ,需要先解壓縮和排序,變成 .dd 映像檔
volatility_2.6_win64_standalone.exe volatility -f hiberfil.sys imagecopy -O [檔案名稱.dd]

下圖為找出與 1524 port 相關之目前所開啟的handles資源
如果看見 $Recycle.Bin 或 SID/RID 要特別注意,通常代表刪除後仍然被佔用的檔案,或是帳號被挾持。
volatility_2.6_win64_standalone.exe -f [映像檔] --profile=[Suggested profile] handles -p [port]
