Malicious Document Analysis - PDF Sample #5
In the above video
tutorial, we analyse a PDF document for IOC's (Indicators of
Compromise). We utilise 1 VM (Virtual Machine) connected on a
Host-Only network (Can't connect to the internet). So the malware
sample, can't infect your own computer, this is a critical step when
analysing malware in your own virtualised lab.
FlareVM Utilities
sha256sum.exe - For fingerprinting (hash value) and checking against the VirusTotal database.
md5sum.exe - For fingerprinting (hash value) and checking against the VirusTotal database.
file - To determine file type (malicious actor may hide true file type for social engineering reasons).
pdfid.py - Overview/Directory of document.
pdf-parser.py - Parses all objects contained in the document.
pdfstreamdumper.exe - Parses and decodes all objects/streams in the document.
| -The pipe is used to process the preceding data, in the context of the latter.
Shortcut Commands
Ctrl A - Places cursor at the beginning of the prompt.
Ctrl E - Places cursor at the end of your typed command/query.
Ctrl U - Deletes content preceding cursor, up to the beginning of the prompt.
Ctrl L - Clears the screen.
Tab - Autocompletes command.
Up Arrow - Iterates through command history.
Ctrl Alt T - Open a new Terminal.
Tools
Cmder - Terminal comprising both Windows/Linux commands/utilities.
Notepad - For making notes whilst performing analysis.
HxD - Hexcode editor.
Sample
Visit: https://bazaar.abuse.ch/browse/
To search for malware samples on the repository, the format used is as follows;
Hashing Algorithm(i.e. md5/sha256) followed by : Hash Value
Example;
md5:63e5685dcc0afd72bc2bbaee5d8dbecc
or
sha256:5ec107d1b9066fdaf6816b82f31a62808892c14c03621cc0969ed21fdbf83d50
Tips/Advice
- Be inquisitive and try to figure things out for yourself.
- Conduct your own research by utilising the plethora of sources/tools available.
- Google/Youtube if you are stuck or unsure about something.
- Set up a virtualised lab environment to perform your own malware analysis.
- Utilise virtualisation software (VMWare/VirtualBox etc).
- Utilise pre-configure VM's (FlareVM/Remnux etc).
- Always ensure when starting your VM's the network adapters are set to Host-Only.
- Be brave! nothing is unattainable, if you apply yourself correctly.
When
downloading/analysing malware, it's critical to know what you are
doing. If you are not confident in your abilities at this juncture, be
prudent and work on your foundational knowledge (OS Systems, Networking,
Security etc) instead.
Literally, it's best to be safe than sorry.
The
repository link above contains real malware samples from the wild. They
all, will almost certainly, do untold damage to your systems
(Computers/Network), and even yourself as an individual, if not handled
correctly.
Comments
Post a Comment
Decorum please