malwaredynamicanalysis05 -...

22
1

Upload: phungquynh

Post on 11-Jun-2018

220 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

1  

Page 2: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

2  

Page 3: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

3  

Page 4: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

[References]  •  Joe  Sandbox,  h0p://www.joesecurity.org/index.php/joe-­‐sandbox-­‐standalone  •  GFI  Sandbox,  h0p://www.gfi.com/malware-­‐analysis-­‐tool  •  Cuckoo  Sandbox,  h0p://www.cuckoosandbox.org  •  ThreatExpert,  h0p://www.threatexpert.com/submit.aspx  •  GFI  ThreaetTrack,  h0p://www.threa0rack.com/  •  Anubis,  h0p://anubis.iseclab.org/      [Image  Sources]  •  h0p://plannerwire.net/wp-­‐content/uploads/2011/02/Playing-­‐

Sandbox_meeNng_planners.gif    

4  

Page 5: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

[References]  •  Cuckoo  Sandbox  Book,  h0p://docs.cuckoosandbox.org/en/latest    [Image  Sources]  •  h0p://www.cuckoosandbox.org/graphic/cuckoo.png    

5  

Page 6: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

6  

Page 7: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

7  

Page 8: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

8  

Page 9: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

[References]  •  MAEC,  h0ps://maec.mitre.org      

9  

Page 10: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

[References]  •  MAEC  Use  Cases,  h0p://maec.mitre.org/language/usecases.html  •  MAEC  in  Use,  h0p://maec.mitre.org/about/inuse.html    [Image  Sources]  •  h0p://maec.mitre.org/language/images/usecases-­‐1.jpg  

10  

Page 11: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

11  

Page 12: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

12  

Page 13: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

13  

Page 14: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

14  

Page 15: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

15  

Page 16: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

16  

Page 17: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

17  

Page 18: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

18  

Page 19: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

[References]  •  Andrew  Davis,  Leveraging  the  ApplicaNon  CompaNbility  Cache  in  Forensic  

InvesNgaNons,  h0ps://dl.mandiant.com/EE/library/Whitepaper_ShimCacheParser.pdf  

19  

Page 20: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

20  

Page 21: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

21  

Page 22: MalwareDynamicAnalysis05 - OpenSecurityTrainingopensecuritytraining.info/MalwareDynamicAnalysis_files/...CUC oo Cuckoo Sandbox Open source automated malware analysis system Analyzes

22