<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M-unition &#187; Malware Rating Index</title>
	<atom:link href="http://blog.mandiant.com/archives/tag/malware-rating-index/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.mandiant.com</link>
	<description>The Ammunition You Need to Find Evil and Solve Crime</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:18:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Memory Analysis on Windows 2003 64-bit and What&#8217;s Next</title>
		<link>https://blog.mandiant.com/archives/846?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=memory-analysis-windows-2003-64bit</link>
		<comments>https://blog.mandiant.com/archives/846#comments</comments>
		<pubDate>Mon, 15 Mar 2010 19:47:51 +0000</pubDate>
		<dc:creator>Jamie Butler</dc:creator>
				<category><![CDATA[The Suite Spot]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[Black Hat USA]]></category>
		<category><![CDATA[CanSecWest]]></category>
		<category><![CDATA[Malware Rating Index]]></category>
		<category><![CDATA[Memory analysis]]></category>
		<category><![CDATA[memory forensics]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MRI]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=846</guid>
		<description><![CDATA[<ul>
<p>Peter and I have been busy planning for <a href="http://cansecwest.com/dojomemory.html">CanSecWest</a> in a week. The course, <a href="http://cansecwest.com/dojomemory.html">Advanced Memory Forensics in Incident Response</a>, is constantly evolving. It has been about a year and a half since <a href="http://www.mandiant.com/products/free_software/memoryze">Memoryze</a> was released, and just over a year for <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer">Audit Viewer</a>.</p> <a href="https://blog.mandiant.com/archives/846" class="read_more">Read the rest</a></ul>]]></description>
			<content:encoded><![CDATA[<ul>
<p>Peter and I have been busy planning for <a href="http://cansecwest.com/dojomemory.html">CanSecWest</a> in a week. The course, <a href="http://cansecwest.com/dojomemory.html">Advanced Memory Forensics in Incident Response</a>, is constantly evolving. It has been about a year and a half since <a href="http://www.mandiant.com/products/free_software/memoryze">Memoryze</a> was released, and just over a year for <a href="http://www.mandiant.com/products/free_software/mandiant_audit_viewer">Audit Viewer</a>. Honestly, it seems a lot longer, but that is not a bad thing. This week my team will be handing over to QA Windows 2003 64-bit support. While that is in testing, Peter will be making improvements to Audit Viewer that you the user have recommended, and he will be verifying everything works correctly with the 64-bit output. <a href="http://www.mandiant.com/uploads/presentations/DoD_2010_PS.pdf">The Malware Rating Index (MRI)</a>, which is in Audit Viewer, really changes the case studies in the training. For some exercises, we have to turn MRI off because the malware becomes obvious if you know how to use the tool. I expect MRI will evolve a lot over the next six months as we think of news ways to visualize, sort, and search the data as well as identify new pieces of data to collect. If you are curious how visualization and sorting can help, check out how <a href="http://windowsir.blogspot.com/2009/12/investigating-breaches.html">Harlan Carvey</a> and <a href="http://thedigitalstandard.blogspot.com/2010/03/ram-analysis-part-2.html">Chris Pogue</a> use it.
</ul>
<ul>
<p>We have gotten a lot of great feedback from the user community, but what Windows operating system support or feature would you like see next? Yes, <a href="http://www.mandiant.com/index.php/products/core/intelligent_response">MANDIANT Intelligent Response</a> has a roadmap, but Memoryze allows us to play a little bit. It is really a labor of love. So let us know what you think. You can reach us at peter.silberman or james.butler plus company name.com. We currently support:</p>
<ol>
- Windows 2000 SP4<br />
- Windows XP SP2 and SP3<br />
- Windows Vista SP1 and SP2 (better installer coming in next release)<br />
- Windows 2003 SP1 and SP2<br />
- Windows 2003 SP2 64-bit (** next release **)
</ol>
</ul>
<ul>
<p>So if you cannot make the training at CanSecWest in a week, <a href="http://www.blackhat.com/html/bh-us-10/training/bh-us-10-training_jb-mf.html">Black Hat USA</a> has just opened their training schedule, and we will be there for the weekend and weekday offerings of Advanced Memory Forensics in Incident Response. I hope to see you soon. Keep your eyes open for official update releases of Memoryze/Audit Viewer and <a href="http://www.mandiant.com/presentations/fresh_prints_malware_behaving_badly/">Webinars/presentations</a>.</ul>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/846/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware Behaving Badly: Preview</title>
		<link>https://blog.mandiant.com/archives/810?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=malware-behaving-badly-preview</link>
		<comments>https://blog.mandiant.com/archives/810#comments</comments>
		<pubDate>Fri, 12 Feb 2010 15:29:11 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[The Suite Spot]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[CanSecWest]]></category>
		<category><![CDATA[Fresh Prints Malware Behaving Badly]]></category>
		<category><![CDATA[Malware Behaving Badly]]></category>
		<category><![CDATA[Malware Rating Index]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MRI]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=810</guid>
		<description><![CDATA[<p>Hope everyone on the northern east coast is staying warm during snowpaclypse. Since I can’t go anywhere I figured now is the right time to write about an upcoming webinar I am giving with Michael Graven.</p>
<p>The webinar entitled<em> Malware Behaving Badly</em> is on Thursday, February 18, at 2:00 p.m. <a href="https://blog.mandiant.com/archives/810" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hope everyone on the northern east coast is staying warm during snowpaclypse. Since I can’t go anywhere I figured now is the right time to write about an upcoming webinar I am giving with Michael Graven.</p>
<p>The webinar entitled<em> Malware Behaving Badly</em> is on Thursday, February 18, at 2:00 p.m. EST. The webinar title is a cute play on my DOD Cyber Crime (DC3) <a href="http://www.mandiant.com/uploads/presentations/DoD_2010_PS.pdf">talk </a>where I first introduced Malware Rating Index (MRI) into <a href="http://www.mandiant.com/products/research/mandiant_audit_viewer/">Audit Viewer</a> (which is available for download).</p>
<p>If you saw my DC3 talk or viewed the slides and are wondering, “hey is this the same talk?” the answer is&#8230;well a little bit. The webinar will build off of a lot of the behaviors and theories I discussed at DC3. We will be addressing new behaviors as well as looking at APT vs Mass Malware behaviors.  I’ve added two new configurable behaviors to MRI and did enough research to scrap a third. I’ll share those as well as give more real world examples of how malware exposes itself in memory.</p>
<p>For example the below listing shows the keylogger, the process and the file handle that process has. The file handle is actual the log file the key logger is writing too.</p>
<table style="height: 158px;" border="0" cellspacing="0" cellpadding="0" width="667">
<col span="3" width="256"></col>
<tbody>
<tr>
<td width="256" height="39">Keylogger Name</td>
<td width="256">Process</td>
<td width="256">Log File</td>
</tr>
<tr>
<td width="256" height="39">Klog</td>
<td width="256">System</td>
<td width="256">\Klog.txt</td>
</tr>
<tr>
<td width="256" height="39">Advanced Keylogger</td>
<td width="256">Explorer</td>
<td width="256">\WINDOWS\Help\dsclientsock.hlp</td>
</tr>
<tr>
<td width="256" height="39">Spector Pro</td>
<td width="256">Explorer</td>
<td width="256">\WINDOWS\system32\avoxnot\BEC7CA9645B2AF87DEEACD53B38B223FEE1C605C.zup</td>
</tr>
</tbody>
</table>
<p>If you didn’t catch my DC3 talk and didn’t understand the slides this is a good time to get an updated version of the talk. I&#8217;m going to focus on malware behavior, what it does when it&#8217;s installed that makes it stand out in memory. We will cover APT and Mass Malware, and specifically where we see their behaviors intersect. Some of these behaviors are horribly simple, i.e. flag svchost launched from directories other than \windows\system32. Some are as simple but may not be as obvious, for example flag svchost, or iexplore if they have a process handle to cmd.exe. These are rules that should never be true.</p>
<p>When discussing rules, I use that term loosely. Basically in Audit Viewer you now have the option to configure all this information. If you go to Operations -&gt; Configure Malware Rating Index you can configure all these things and a few more not mentioned in this post but mentioned in the webinar. We will wrap up the webinar like always with a live demo. Live demos are the most fun really, it’s like NASCAR except it&#8217;s just reputation not lives on the line.</p>
<p>I hope you can <a href="https://cc.readytalk.com/cc/schedule/display.do?udc=wh0b6ijw44nk">join us</a>, it should be fun.</p>
<p>If you would like to learn more in-depth about how physical memory analysis works, use <a href="http://www.mandiant.com/products/free_software/memoryze/">Memoryze</a> and Audit Viewer, understand MRI, or write your own malware rules, join Jamie and I at the <a href="http://cansecwest.com/dojomemory.html">CanSecWest training</a>. CanSecWest specializes in technical, hands-on classes with an extremely low student-teacher ratio.</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/810/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Audit Viewer: Malware Rating Index Undocumented Features and Caveats</title>
		<link>https://blog.mandiant.com/archives/782?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=audit-viewer-malware-rating-index-undocumented-features-caveats</link>
		<comments>https://blog.mandiant.com/archives/782#comments</comments>
		<pubDate>Tue, 09 Feb 2010 14:48:42 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[The Armory]]></category>
		<category><![CDATA[The Suite Spot]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[DC3]]></category>
		<category><![CDATA[DOD Cyber Crime Conference]]></category>
		<category><![CDATA[M-Trends]]></category>
		<category><![CDATA[Malware Rating Index]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MRI]]></category>
		<category><![CDATA[MTrends]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=782</guid>
		<description><![CDATA[<p>Hopefully everyone has had a few weeks to recover from the M-Trends kickoff party in St. Louis and everyone has also had a chance to read the <a href="http://www.mandiant.com/news_events/article/m-trends/">M-Trends report</a>! I hope everyone enjoyed the talk I gave at DOD Cyber Crime Conference. <a href="https://blog.mandiant.com/archives/782" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hopefully everyone has had a few weeks to recover from the M-Trends kickoff party in St. Louis and everyone has also had a chance to read the <a href="http://www.mandiant.com/news_events/article/m-trends/">M-Trends report</a>! I hope everyone enjoyed the talk I gave at DOD Cyber Crime Conference. I certainly had fun giving it, sorry to those that got hit with the squishy balls. I wanted to take a second to address some caveats and undocumented features of MRI that couldn’t be discussed in the talk.</p>
<p>A caveat within MRI I that I want to talk about is Process Path Verification. This rule set is very powerful but there are two ways to define to paths. Neither is documented because currently there is no documentation on MRI.. The first method of specifying a process path is to specify an absolute path such as this:<br />
<em> calc.exe:\windows\system32</em></p>
<p>MRI interprets this as the only valid path for calc.exe is \windows\system32\calc.exe. However, if I wrote the rule like:<br />
<em> calc.exe:\windows\system32\</em></p>
<p>MRI would interpret this as calc.exe can be run from any sub directory as long it’s a sub directory within \windows\system32\*</p>
<p>The reason this is important is it gives you flexibility in writing definitions. If I don’t want to specify the exact location of iexplore.exe I can say it needs to be launched from \program files\. This may prove to be too loose, and I may change this behavior going forward. For now you have the flexibility to specify absolute paths or sub paths.</p>
<p>The next &#8220;undocumented&#8221; tidbit that I want to discuss is within two behaviors. These behaviors actually have the ability to use regex when trying to match up their values. I did not build the regex option into the UI so it has to be manually added to the AuditViewerConfig.xml. The two XML lists that can take regex expressions are IgnoreFilesList, and ProcessSuspiciousHandleList. The regex elements are, IgnoreFileRegex, and HandleRegex. An example IgnoreFileRegex looks like:<br />
<em>&lt;IgnoreFileRegex&gt;mshist.*\\index.dat&lt;/IgnoreFileRegex&gt;</em></p>
<p>This rule specifies that any file matching this regular expression should be ignored when doing process scoring. You can get creative just be careful.</p>
<p>An example HandleRegex looks like:<br />
<em>&lt;HandleRegex&gt;*:.*-7$:mutant:known conficker mutant&lt;/HandleRegex&gt;</em></p>
<p>It breaks down like this:<br />
Process: Regular Expressions : handle type: description</p>
<p>It breaks down like this:<br />
Process: Regular Expressions : handle type: description</p>
<p>This allows you to get more out of your suspicious handles definitions.</p>
<p>Finally, I’d like to take a second to reiterate something I stated at DC3. The “Verify Digital Signatures” option in <a href="http://www.mandiant.com/products/free_software/memoryze/">Memoryze</a> and <a href="http://www.mandiant.com/products/research/mandiant_audit_viewer/">Audit Viewer </a>wizard can ONLY be run when doing live memory. It is not possible to enable it when doing dead memory analysis. Which means the address scoring is not possible on dead memory, behavioral analysis still works on dead memory. If you are going to acquire memory, please run live analysis jobs as well as acquisition. This way you get the most information possible off the machine. The second thing I wanted to reiterate is that verify digital signatures is great, it really helps potentially speed up an analyst’s job. However, we are only verifying the digital signatures exist and are valid on disk. We are not verifying the module in memory hasn’t been modified. If a userland rootkit exists (again shame on the authors) then we won’t report that. It’s important to remember this. Verifying modules in memory short of doing rootkit detection is not a trivial task. The windows loader is a beast, a behemoth it does a lot to make verification in memory to disk is very hard (not impossible). Thanks again for all the interest in <a href="http://www.mandiant.com/products/services/m-trends">M-Trends</a>, <a href="http://www.mandiant.com/products/research/mandiant_audit_viewer/">Audit Viewer</a> and<a href="http://www.mandiant.com/products/free_software/memoryze/"> Memoryze</a>. As always feedback is always appreciated.</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/782/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DOD Cyber Crime: New Audit Viewer/Memoryze</title>
		<link>https://blog.mandiant.com/archives/741?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dod-cyber-crime-audit-viewermemoryzetalks</link>
		<comments>https://blog.mandiant.com/archives/741#comments</comments>
		<pubDate>Fri, 22 Jan 2010 02:23:15 +0000</pubDate>
		<dc:creator>Peter Silberman</dc:creator>
				<category><![CDATA[The Whiteboard]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[Audit Viewer]]></category>
		<category><![CDATA[DC3]]></category>
		<category><![CDATA[DOD Cyber Crime]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Malware Rating Index]]></category>
		<category><![CDATA[MANDIANT]]></category>
		<category><![CDATA[Memoryze]]></category>
		<category><![CDATA[MRI]]></category>

		<guid isPermaLink="false">http://blog.mandiant.com/?p=741</guid>
		<description><![CDATA[<p>MANDIANT is going to be at DOD Cyber Crime this year. Jamie and I have both been heads down for many weeks now working on some pretty cool stuff. We are starting to come up for air and what that means for you is updates to Memoryze and Audit Viewer. <a href="https://blog.mandiant.com/archives/741" class="read_more">Read the rest</a></p>]]></description>
			<content:encoded><![CDATA[<p>MANDIANT is going to be at DOD Cyber Crime this year. Jamie and I have both been heads down for many weeks now working on some pretty cool stuff. We are starting to come up for air and what that means for you is updates to Memoryze and Audit Viewer. We will be releasing new versions of each that coincide with DC3.  I, along with many of my co-workers, will be presenting and attending. My talk abstract is very ambiguous so I thought I’d take a brief second to discuss both the talk and the changes to Audit Viewer and Memoryze.</p>
<p>The talk is going to be interactive. And dammit I don’t care if you don’t want to interact with me. I&#8217;m both very convincing, persistent and well&#8230;charming! You will feel compelled to join in on this talk. I promise. I know this because I&#8217;m bringing bribes… And yes, I&#8217;m bringing what you are thinking.</p>
<p>This talk will contain a brief intro to memory analysis, a FAQ etc. We are not going to waste much time on the nitty gritty since most people are not interested in how we chop off the last 12 bits to get a physical offset from a virtual address. I know, you just fell asleep a little.  During this talk I will make a case for why memory analysis is important. I will pull from pervious APT investigations where disk analysis failed and had to be used in conjunction with memory analysis. Finally, we will discuss MANDIANT’s Malware Rating Index (MRI). We will finish with real APT incident demos where I&#8217;ll walk through the investigation of an infected system with APT.</p>
<p>Now, a little more about MRI. MRI is a huge update to Audit Viewer.  Instead of going after a fish (malware) with a hook (signatures), I&#8217;m going after fish (malware) with a drag net (MRI). The goal of this feature is twofold. First it is going to  help pinpoint specific processes that should be investigated further while attempting to eliminate some of the non-suspicious processes and get them out of the analyst&#8217;s way. It&#8217;s also designed to try and make APT detection easier. A lot of work went into looking at our samples and how they behave etc, and coming up with definable behaviors that trap those little creatures. MRI is made up of two components. The first component is a definable behavior rule set that is completely customizable. It is made up of three different types of rules:</p>
<ul>
<li>Process Path Verification – allows users to define what processes should be launched from what directories. This triggers on malware that copies and names itself after svchost or other system processes to subdirectories within system folders. For example a default rule is that svchost can only be executed from \windows\system32. Any time we see it running from somewhere else we flag the process.</li>
<li>Process User Verification – allows users to define what processes should be running under what users.  This triggers on malware spawning svchost for purposes of unmapping image bases or hiding dlls within spawned svchost. So, for example, if malware copies itself to system32\dllcache and then names itself svchost.exe, you can define a rule saying svchost.exe should be running as local service, network service, or system. When Audit Viewer see svchost running as administrator it gets flagged.</li>
<li>Process Handle Inspection – this allows you to define specific rules pertaining to malware or generic behavior. For example a default rule is to flag svchost or iexplore anytime it has a process handle to cmd.exe. There is just no good reason for this to _<em>EVER</em>_ happen. You can also define rules based on specific malware, for example if a3c mutant is present then flag the process as being infected with sality.</li>
</ul>
<p>All of these features are configurable from the UI by going to operations -&gt; Configure MANDIANT MRI.</p>
<p>The second component of MRI is a process address space scoring mechanism. We will be releasing an update to Memoryze at DC3. The new release will contain bug fixes as well as a new feature called “Verify Digital Signatures.” When this parameter is turned on memoryze will perform a “digital signature check” on all loaded modules. This can only be enabled on live memory analysis. The digital signature check verifies the module on disk is digitally signed. We do a bunch of math and use our Least Frequency of Occurrence to trust modules that aren&#8217;t signed but occur in more than X% of processes. Where X is defined by the user. We won&#8217;t flag or catch modified binaries in memory. So if a rootkit is doing userland hooking (it should be ashamed) we won&#8217;t know about it because we are checking disk to determine if it is digitally signed. There are a lot of reasons why we can’t verify in memory digital signatures.  It might make an interesting blog to detail all the reasons. With that said, this new feature gives us a good working idea of how much of the loaded modules in the process address space are signed and therefore trusted. It&#8217;s had fantastic results thus far. I’ve been using it on old incidents to see if we could have sped up results using these new methods. The answer seems to be yes in a lot of cases.</p>
<p>After DC3 I’ll have more blogs detailing how you can use and write better rules for MRI. But for now there will be a default distribution that you can use and modify. Again, like always, Audit Viewer is open source and free. Which means you can see the logic and rules behind MRI. Memoryze is and will stay free.</p>
<p>If you are going to be at DC3 and want to grab a beer I will be there from Sun (night)-Weds. Unfortunately I&#8217;m going to be missing all the great talks on Thurs so I can leave to compete in the <a href="http://www.toughguy.co.uk">Tough Guy Challenge</a>. You are more than welcome to join at this race in Northern England. As I understand it there are still some open slots! See everyone at DC3!</p>
]]></content:encoded>
			<wfw:commentRss>https://blog.mandiant.com/archives/741/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

