Showing posts with label forensics. Show all posts
Showing posts with label forensics. Show all posts

Saturday, November 12, 2016

Analyze Macro Code from Malicious Documents

Microsoft office is something i guess everybody uses it and knows about it and you are a regular computer user then to somewhat extent you are definitely going to use Microsoft office or any other variant, so in this particular post we want to show you how malicious documents can be analyzed in order to find malicious macro code. so let's start it.

Malicious Samples


Macro Code is usually written in vba programming for more on it just see the wiki. here i have some malicious sample files which you can get by asking me in comments. they contain some macro code which basically just pings localhost and opens notepad.exe on a windows host.


vba programming
malware asking for enable macro


Thursday, November 10, 2016

Digital Forensics Investigation with Autopsy

autopsy is a digital forensic investigation tool used by military personnels and corporate examiners to investigate which operations were currently performed on a target system, flash drive or specific files. so let's dig into it.

Get Autopsy


first of all we need to get Autopsy from this URL and then install it, upon successful installation you should be greeted with following screen.


forensic autopsy
autopsy first run

Wednesday, November 9, 2016

Dumping Plain text Chat From Memory - Forensic

We've already posted a way to capture ram using Dumpit now in this particular blog post we're going to show you how you can dump clear text chat messages from the memory so let's do it.

Capturing Data


Before Caputring Data We'll quickly use our browser to send some messages so let's do it and im using google hangout messenger.


memory analysis tools
Hangout messages

Sunday, November 6, 2016

Examine Malicious OLE Files - preventing zero day attacks

Microsoft developed OLE technology to combine documents to other objects which hackers also noticed so they tried to use the feature for their own benefit. they tried some micro word 2010 and rich text document also. Let's see how to see a Valid vs a Malicious DOC file.

Are You Ready ?


first create a valid test.doc file which i also created named as Test file.doc i.e micro word document. now its time to perform a quick mimefile analysis on the file, 

ole file analysis
emldump.py -d filename


Saturday, November 5, 2016

Live Physical Memory Analysis - Ram Analysis

Welcome friends, we all know the importance of physical memory i.e RAM and also the importance of it as once the computer is shutdown next time we won't be able to find out which process currently were running on the system before the shut down so we need a quick way to scan the ram i.e physical memory using useful memory analysis tools.

RAM Analysis


I fired up my windows xp machine and gave it 256MB of ram so we can easily analyse it. then i used the DumpIt.exe tool to dump the data out of ram physical memory.

Ram Memory Analysis Forensic
DumpIt.exe

Friday, November 4, 2016

Performing Metadata Forensics Intelligently

Metadata Analysis is something very interesting and untried by most of bug bounty hunters and security researchers, and the Truth is that metadata stuff cold be found in each domain of the information security. See below a little introduction about metadata first before going towards analysis.



What is Metadata ?


metadata basically is something that let's know about details, type, functionality and a couple of other useful things about a specific data. Now this data could be anything, an image, document, binary file, webpage any stupid thing available in the domain of information security.