Friday, September 14, 2018

Digital Forensics: Malware Forensics > Yara



เดิม Admin ศึกษา The Volatility memory forensics framework พบว่ามีการใช้ คำสั่ง yarascan  จึงเริ่มต่อยอด เพิ่มเติมกับ Yara Rule


การจะเขียน rule ได้  เราต้อง แกะ พฤติกรรมของ malware   ลักษะเฉพาะของมัลแว ตัวนั้นเช่น ข้อความ ,จุดที่เขียนใน registry, การสร้างไฟล์  ,hash มีหลายอย่างประกอบ  นำมาเขียน yara Rule


#Yara –Help

เริ่ม เขียน Yara Rule WildcardExample

 แบ่งเป็น  meta , String , condition  


String
  • Hexadecimal strings, which are useful for defining raw bytes;
  • Text strings;
  • Regular expressions.

  rule Myrule
{
    
    Meta:  
 
         Description = “Test Yara rules”
          Author = “Neo”
 
    strings:
        $s1 = "Hellow World"
         $s2 = "c99.php"  fullword ascii
 
 
    condition:
        1 of ($s)
 
}

.........................................................................................




rule WildcardExample
{
    strings:
       $hex_string = { E2 34 ?? C8 A? FB }

    condition:
       $hex_string
}

.........................................................................................



เริ่ม เขียน Yara Rule Metasploit Meterpreter
        rule My_Meterpreter
{
    
    Meta:  
 
         Description = “Test Yara rules Meterpreter
          Author = “Neo”
 
    strings:
        $s1 = "MACHINE\SYSTEM\CONTROLSET001\SERVICES\WINSOCK2\PARAMETERS\PROTOCOL_CATALOG9"
        $st1 = "MACHINE\SYSTEM\CONTROLSET001\SERVICES\WINSOCK2\PARAMETERS\NAMESPACE_CATALOG5 "
        $su1 = "MACHINE\SYSTEM\CONTROLSET001\CONTROL\NLS\CUSTOMLOCALE"
        $s4 = "MACHINE\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS"
 
 
    condition:
        all of ($s*)  or (all of (st*) and of (su*))
 
}


# yara -w -m /root/Desktop/Yara/*.yar /root/Desktop/Dump/winxp.vmem
                                      
           ใช้คำสั่ง yara ตรวจสอบ  ไฟล์ dump memory   ชื่อ winxp.vmem




หมายเหตุ สรุป :  ให้เราเอา staring  จาก IOC  มาใส่ใน Yara rule  เป็นเทคนิคลดเวลาในการสร้าง  Yara rule  อย่างหนึ่ง  อ. ของ admin ได้กล่าวไว้

Indicator of compromise (IOC) — in computer forensics is an artifact observed on a network or in an operating system that with high confidence indicates a computer intrusion. Typical IOCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs or domain names of botnet command and control servers.

 
ดูตัวอย่าง Rule ได้ที่

https://yara.readthedocs.io/en/v3.4.0/writingrules.html
https://www.bsk-consulting.de/loki-free-ioc-scanner/
https://en.wikipedia.org/wiki/Indicator_of_compromise
https://blog.malwarebytes.com/security-world/technology/2017/09/explained-yara-rules/
https://securityintelligence.com/signature-based-detection-with-yara/
https://www.joesandbox.com
https://github.com/Yara-Rules
#Malware Forensics 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Thursday, September 13, 2018

Digital Forensics: Belkasoft Acquisition Tool

Digital Forensics: Belkasoft Acquisition Tool 

ทดสอบการสร้าง Forensics Disk Image โดยใช้โปรแกรม Belkasoft Acquisition Tool

Belkasoft Acquisition Tool (or BelkaImager) allows you to make images of hard and removable drives, Android and iOS devices, and download Cloud data.

Belkasoft Acquisition Tool helps investigators to complete one of the most important steps of investigation: obtaining data from a data source. Four types of data sources are currently supported:

  • Hard or removable drives
  • Mobile devices
  • Computer RAM memory
  • Cloud data
The acquired image can be then analyzed with Belkasoft Evidence Center or any third-party tool.

ทดสอบโปรแกรม Belkasoft Acquisition Tool เป็นเครื่องมือที่ใช้สำหรับทำ Forensics Disk Image

กับ Kingston  DataTraveler 8 GB ผ่าน write Blocker 

1.ทำการ Download โปรแกรม ฺBelkasoft จาก https://belkasoft.com/trial

    สิ่งสำคัญในการทำ Disk Image  ต้องผ่านอุปกรณ๋ Write Blocker เพื่อป้องกันการเขียนทับหลักฐาน (Evidence)

Write Blocker
Forensic Data Acquisition - Hardware Write Blockers
Credit:DFIR.Science youtube


2. ทำการ เลือก G:Drive Kingston  DataTraveler 8 GB ที่ต้องการทำ Disk Image (\\Physicaldrive1)


3. ตั้งชื่อไฟลฺ์ CF-SM-FD-BA01.001 เป็น Raw ไฟล์

4.เมื่อทำเสร็จแล้วตรวจสอบ Hash Value

MD5 Hash : 0eec2711d4595b8e9a5294e50d79ee66c





ศึกษาเพิ่มเติมได้ที่ Free computer forensic tools 

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud 

Saturday, September 8, 2018

Digital Forensics: Email tracking for gmail

Digital Forensics: Email tracking for gmail

สอนทำ Email Tracking วิธีดูว่าอีเมลที่เราส่งออกไปถูกเปิดอ่านหรือยัง


มันคือAPP ที่คอย track ว่าอีเมลที่เราส่งไป นั้นถูกเปิดอ่านหรือเปล่า? หากคุณทำงานที่ต้องใช้อีเมลในการสื่อสารกับลูกค้าและทีมงานเป็นหลัก การได้รู้ว่าอีเมลถูกเปิดอ่านหรือไม่
 1. เปิด Google Chrome Browser เพื่อติดตั้ง Extension ไปที่ Install Extension
Email Tracking for Gmail - Mailtrack
Email Tracking

2. กด Sign In with Google อนุญาตให้ Mailtrack เข้าถึงบัญชีของเรา
Check Mail track Enabled

3.เลือกว่าจะใช้งานแบบ เลือก Free 



4. ทำการทดลองส่งเมล Test Track

5. ไปที่ จดหมายที่ส่งแล้ว (Sent Item)เราก็จะเห็นเครื่องหมายถูกสองอัน ถ้าขึ้นเขียวสองอันแปลว่าคนที่เราส่งไปเปิดเมลแล้ว   





 Email Tracking Software (Browser Extension)


How to Track Sent Emails on Gmail Using Chrome


ที่มา:
mailtrack
mailmaster
bowkraivanich

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Wednesday, September 5, 2018

Digital Forensics: GUYMAGER Acquisition Tool

Digital Forensics: GUYMAGER Acquisition Tool


 บทความนี้จะเน้นเกี่ยวกับพื้นฐานเกี่ยวกับการเก็บหลักฐาน

 ทดสอบ การสร้าง Forensic Image โดยใช้โปรแกรม GUYMAGER

GUYMAGER Acquisition Tool  กับ Kingston  DataTraveler 8 GB  โดยใช้เครื่อง Macbook pro เป็นเครื่องทำสำเนาหลักฐาน

1.โปรแกรม Guymager จะอยู่รวมใน Deft  ให้ทำการ Download โปรแกรม deft   ซึ่งเป็น Linux Live ไฟล์ ISO 

 
    หมายเหตุ : การทดสอบนี้ ไม่ได้ผ่านอุปกรณ์     Hardware Write Blocker    

 

2. ทำการ  Boot คอมพิวเตอร์ จาก แผ่น DVD Deft  แล้ว เปิดโปรแกรม Guymager

 

3. เลือก  Disk ที่จะทำ Image  ใช้คำสั่ง  Acquire Imageทำการ  ตั้งชื่อไฟล์  CFSMGuy01.E01 

4.เมื่อทำเสร็จแล้วตรวจสอบ Hash Value

MD5 Hash : 0eec2711d4595b8e9a5294e50d79ee66c

 เมื่อทำเสร็จจะได้ Report  แสดงรายละเอียด Forensic Image , Flash Drive ,ค่า Hash MD5,SHA1 


DEFT Zero (2018.2) ready for download

Support for the new Apple Macbook and Macbook Pro


As promised, here the link to download the new DEFT Zero, the first Linux live distro “sugar free”
Remember that DEFT Zero is designed for the cloning machines, less than 650 megabytes in ram!
Iso: http://na.mirror.garr.it/mirrors/deft/zero/deftZ-2018-2.iso
Md5: cd410c27ac580f0efd1d7eab408b4edb
What’s new?
– Official support for the new Apple Macbook and Macbook Pro
– Guymager 0.8.8 with Afflib support
– VeraCrypt 1.22
– Resource controll panel integrated on the desktop
– Root password: “deft”
If there are problems or bugs, report them to us as well! Thank you!
Enjoy DEFT!

  







สามารถ Download CFSMGuy01.info Report

หมายเหตุ: (Acquisition Stage) สิ่งสำคัญในการทำ Disk Image  ควรผ่านอุปกรณ๋ Write Blocker เพื่อป้องกันการเขียนทับหลักฐานต้นฉบับ (Original Evidence) และเป็นผลดีต่อพยานหลักฐาน  (ACPO,2012)

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Data Breach Check

Data Breach Check Data Breach Check EP.4 “คิด ก่อน Prompt” AI อาจช่วยคุณทำงานได้เร็วขึ้น แต่บางครั้ง…ข้อมูลสำคัญก็อาจ “หลุดออกไป” โดยไม่รู้...