728x90

์•…์„ฑ์ฝ”๋“œ

  • ์˜๋„์ ์œผ๋กœ ์ปดํ“จํ„ฐ ์‚ฌ์šฉ์ž์—๊ฒŒ ํ”ผํ•ด๋ฅผ ์ฃผ๊ณ ์ž ๋งŒ๋“  ์•…์˜์ ์ธ ํ”„๋กœ๊ทธ๋žจ
  • ๊ธฐ์กด์˜ ํŠธ๋กœ์ด๋ชฉ๋งˆ, ์• ๋“œ์›จ์–ด, ๋ฐฑ๋„์–ด, ๋ฃจํŠธํ‚ท ๋“ฑ์˜ ์•…์„ฑ์ฝ”๋“œ์— ๋”ํ•ด, ์ตœ๊ทผ์—๋Š” ๊ธˆ์ „์  ๋ชฉ์ ์„ ์ฃผ๋กœ ๋“œ๋กœํผ, ๋‹ค์šด๋กœ๋”, ํ‚ค๋กœ๊ฑฐ, ๋งˆ์ด๋„ˆ, ๋žœ์„ฌ์›จ์–ด ๋“ฑ ๋‹ค์–‘ํ•œ ํ˜•ํƒœ๋กœ ์ง„ํ™”ํ•ด ๋‚˜๊ฐ€๊ณ  ์žˆ์Œ

๊ด€๋ จ ํ”„๋กœ๊ทธ๋žจ

๋จธ์‹ ๋Ÿฌ๋‹ ๊ด€๋ จ: ์ฝ”๋žฉ

๋ฆฌ๋ฒ„์‹ฑ ๊ด€๋ จ: x64dbg, x32dbg

https://sean.tistory.com/380

 

x64dbg(x32dbg) ๋‹ค์šด๋กœ๋“œ ๋ฐ ํŒจํ‚ค์ง€ ๋งค๋‹ˆ์ € ์‚ฌ์šฉ

https://sourceforge.net/projects/x64dbg/files/snapshots/ ์œ„์˜ URL์— ์ ‘์†ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์ด SOURCEFORGE์—์„œ Snapshot ํ˜•ํƒœ๋กœ ๋ฐฐํฌ๋œ๋‹ค. "Download Latest Version" ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ Snapshot ํ˜•ํƒœ์˜ x64dbg๋ฅผ ๋‹ค์šด๋กœ๋“œํ•œ๋‹ค. ๋‹ค์šด๋กœ๋“œ

sean.tistory.com

์•…์„ฑ์ฝ”๋“œ ๊ด€๋ จ: PEView, pestudio

http://wjradburn.com/software/(PEView)

https://www.winitor.com/download(pestudio)


 

์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ๋ฐฉ๋ฒ•์˜ ๊ฐˆ๋ž˜

์ •์  ๋ถ„์„

  • ํŒŒ์ผ์„ ์‹คํ–‰ํ•˜์ง€ ์•Š๊ณ  ํŒŒ์ผ์˜ ์ข…๋ฅ˜(exe, dll, doc, zip ๋“ฑ), ํฌ๊ธฐ, ํ—ค๋”(PE) ์ •๋ณด, Import/Export API, ๋‚ด๋ถ€ ๋ฌธ์ž์—ด, ์‹คํ–‰ ์••์ถ• ์—ฌ๋ถ€, ๋“ฑ๋ก ์ •๋ณด, ๋””๋ฒ„๊น… ์ •๋ณด, ๋””์ง€ํ„ธ ์ธ์ฆ์„œ ๋“ฑ์˜ ๋‹ค์–‘ํ•œ ๋‚ด์šฉ์„ ํ™•์ธํ•˜๋Š” ๊ฒƒ
  • ๋””์Šค์–ด์…ˆ๋ธ”๋Ÿฌ๋„ ์ •์ ๋ถ„์„์˜ ์ผ๋ถ€๋กœ ๋ณธ๋‹ค.

๋™์  ๋ถ„์„

  • ํŒŒ์ผ์„ ์ง์ ‘ ์‹คํ–‰์‹œ์ผœ์„œ ํ–‰์œ„๋ฅผ ๋ถ„์„ํ•˜๊ณ , ๋””๋ฒ„๊น…์œผ๋กœ ์ฝ”๋“œ ํ๋ฆ„๊ณผ ๋ฉ”๋ชจ๋ฆฌ ์ƒํƒœ ๋“ฑ์„ ์ž์„ธํžˆ ์‚ดํŽด๋ณด๋Š” ๊ฒƒ
  • ํŒŒ์ผ, ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ, ํ”„๋กœ์„ธ์Šค, ๋„คํŠธ์›Œํฌ ๋“ฑ์„ ๊ด€์ฐฐํ•˜๋ฉฐ ํ–‰์œ„๋ฅผ ๋ถ„์„ํ•˜๊ณ , ๋””๋ฒ„๊ฑฐ๋ฅผ ์ด์šฉํ•ด ํ”„๋กœ๊ทธ๋žจ ๋‚ด๋ถ€ ๊ตฌ์กฐ์™€ ๋™์ž‘ ์›๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜๊ธฐ๋„ ํ•จ

ํŒจํ‚น ์—ฌ๋ถ€ ํ™•์ธ(by. PEID), ์ž๋™ํ™” ๋ถ„์„(by. Cuckoo, Hybrid analysis ๋“ฑ)

 

  • s/w๊ฐ€ ๋ฆฌ๋ฒ„์Šค์—”์ง€๋‹ˆ์–ด๋ง์„ ๋ง‰๊ธฐ ์œ„ํ•ด ์•”ํ˜ธํ™”ํ•˜๊ฑฐ๋‚˜ ์‹คํ–‰ํŒŒ์ผ์„ ์••์ถ•ํ•˜์—ฌ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ณผ ์ˆ˜ ์—†๊ฒŒ ๋งŒ๋“œ๋Š” ๊ฒƒ = ํŒจํ‚น
  • ์ •์  ๋ถ„์„: PEView, VirusTotal, strings, Dependency Walker, Resource Walker
    • IDA ๊ฐ™์€ ๋””์Šค์–ด์…ˆ๋ธ”๋Ÿฌ๋กœ ๋‚ด๋ถ€ ์ฝ”๋“œ๋กœ ๊ตฌ์กฐ๋ฅผ ๋ณด๋Š” ๊ฑด ๊ณ ๊ธ‰ ์ •์ ๋ถ„์„์œผ๋กœ ๋ถ„๋ฅ˜
  • ๋™์  ๋ถ„์„: process monitor, RegShot, process explorer, wireshark, SysAnalyzer
    • Ollydbg, x64dbg ๊ฐ™์€ ๋””๋ฒ„๊ฑฐ๋กœ ํ”„๋กœ๊ทธ๋žจ ๋‚ด๋ถ€ ๊ตฌ์กฐ์™€ ๋™์ž‘์›๋ฆฌ๋ฅผ ๋ณด๋Š” ๊ฑธ ๊ณ ๊ธ‰ ๋™์ ๋ถ„์„์œผ๋กœ ๋ถ„๋ฅ˜

 

KISA_Malware Features.pdf
1.00MB

 

  • ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ(Metadata): ๊ธฐ๋ณธ์ ์ธ ํŒŒ์ผ์ •๋ณด์™€ PE์ •๋ณด
  • ์ •์ ์ •๋ณด(Static Info): ๊ฐœ๋ฐœ๊ฒฝ๋กœ ๋ฐ ๋ฌธ์ž์—ด ๋“ฑ ์ฝ”๋“œ ๋‚ด์—์„œ ํ™•์ธ ๊ฐ€๋Šฅํ•œ ์ •๋ณด
  • ๋™์ ์ •๋ณด(Dynamic Info): ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ, ํ”„๋กœ์„ธ์Šค ๋“ฑ ์•…์„ฑ์ฝ”๋“œ ์‹คํ–‰ ์‹œ ๋™์ž‘ํ•˜๋Š” ์ฃผ์š” ํ–‰์œ„ ์ •๋ณด
  • ๋„คํŠธ์›Œํฌ(Network): ์•…์„ฑ์ฝ”๋“œ ์‹คํ–‰ ์‹œ ์ ‘์† ์‹œ๋„ ๋ฐ ํŒŒ์ผ/๋ฉ”๋ชจ๋ฆฌ ๋‚ด ํฌํ•จ๋œ URL/IP
  • ATT&CK Matrix: ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์ „๋žต, ์ „์ˆ  ๋ณ„(TTPs) ํ–‰์œ„๋ฅผ ๊ธฐ์ˆ ๋‹จ์œ„ ๋ณ„๋กœ ์ถ”์ถœํ•œ ์ •๋ณด
  • ๊ธฐํƒ€ ์ •๋ณด(ETC): ์•…์„ฑ์ฝ”๋“œ ํ•จ์ˆ˜ ๋‹จ์œ„ ๋“ฑ์˜ ์ •๋ณด์™€ ์•…์„ฑ ๋ฌธ์„œ์— ๋Œ€ํ•œ ์ •๋ณด

https://github.com/a-tartarelli/malware-detection

 

GitHub - a-tartarelli/malware-detection: Malware detection using machine learning and deep learning algoritms based on O.S. API

Malware detection using machine learning and deep learning algoritms based on O.S. API calls - a-tartarelli/malware-detection

github.com

 

https://github.com/OmerFarukKurklu/cnn-malware-classification

 

GitHub - OmerFarukKurklu/cnn-malware-classification: Classifying malware families by converting their binaries to images and the

Classifying malware families by converting their binaries to images and then applying Convolutional Neural Network solutions. - OmerFarukKurklu/cnn-malware-classification

github.com

 

'EVI$ION > ์ธ๊ณต์ง€๋Šฅ ์•…์„ฑ์ฝ”๋“œ ๋ถ„๋ฅ˜' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[STUDY] #WEEK3 - QUIZ  (0) 2024.10.04
[SESSION] 3. PEํŒŒ์ผ(2)  (1) 2024.10.04
[STUDY] #WEEK2 - QUIZ  (0) 2024.09.24
[SESSION] 2. PEํŒŒ์ผ  (0) 2024.09.24
[SESSION] 1. ๋ฆฌ๋ฒ„์‹ฑ ๊ธฐ์ดˆ  (0) 2024.09.22

+ Recent posts