- or how Microsoft's WOW64 technology
unintentionally fools IT Security analysts
Christian Wojner, CERT.at
1 29.11.2012
- or how Microsoft's WOW64 technology unintentionally fools IT - - PowerPoint PPT Presentation
- or how Microsoft's WOW64 technology unintentionally fools IT Security analysts Christian Wojner, CERT.at 29.11.2012 1 Wh01am Person Publications Speaker Christian Wojner Papers FIRST Symposium 2010 Malware Analysis, Reverse
Christian Wojner, CERT.at
1 29.11.2012
29.11.2012 2
Engineering, Computer Forensics
Functionality
Minibis
Technical Seminar 2012
Prague 2012
29.11.2012 3
29.11.2012 4
29.11.2012 5
29.11.2012 6
29.11.2012 7
29.11.2012 8
29.11.2012 9
29.11.2012 10
29.11.2012 11
29.11.2012 12
29.11.2012 13
29.11.2012 14
29.11.2012 15
29.11.2012 16
Access to ... ... is redirected to ... Folders %windir%\System32\ %windir%\SysWOW64\ %windir%\lastgood\system32\ %windir%\lastgood\SysWOW64\ Files %windir%\regedit.exe %windir%\SysWOW64\regedit.exe
a. using local tools b. using online services
29.11.2012 17
29.11.2012 18
32 Bit 64 Bit C:\Windows\SysWOW64\ieapfltr.dll C:\Windows\system32\ieapfltr.dll ee9d715af1b928982f417238b9914484 8eada158d964e3fd1999ad96c9c507ff Malicious! Good!
29.11.2012 19
32 Bit 64 Bit C:\Windows\SysWOW64\ieapfltr.dll C:\Windows\system32\ieapfltr.dll ee9d715af1b928982f417238b9914484 8eada158d964e3fd1999ad96c9c507ff Malicious! Good!
29.11.2012 20
32 Bit 64 Bit C:\Windows\SysWOW64\ieapfltr.dll C:\Windows\system32\ieapfltr.dll ee9d715af1b928982f417238b9914484 8eada158d964e3fd1999ad96c9c507ff Malicious! Good!
29.11.2012 21
29.11.2012 22
29.11.2012 23
29.11.2012 24
29.11.2012 25
WOW64 Filesystem Redirector
29.11.2012 26
WOW64 Filesystem Redirector
29.11.2012 27
29.11.2012 28
29.11.2012 29
32 Bit 64 Bit C:\Windows\SysWOW64\ieapfltr.dll C:\Windows\system32\ieapfltr.dll ee9d715af1b928982f417238b9914484 8eada158d964e3fd1999ad96c9c507ff Malicious! Good!
29.11.2012 30
29.11.2012 31
29.11.2012 32
29.11.2012 33
Registry‐Key Before
Windows 7 and Server 2008 R2
Since
Windows 7 and Server 2008 R2
HKLM\SOFTWARE HKLM\SOFTWARE\Classes HKLM\SOFTWARE\Classes\Appid HKLM\SOFTWARE\Classes\CLSID HKLM\SOFTWARE\Classes\DirectShow HKLM\SOFTWARE\Classes\Interface HKLM\SOFTWARE\Classes\Media Type HKLM\SOFTWARE\Classes\MediaFoundation HKLM\SOFTWARE\Clients HKLM\SOFTWARE\Microsoft\COM3 HKLM\SOFTWARE\Microsoft\EventSystem HKLM\SOFTWARE\Microsoft\Notepad\DefaultFonts HKLM\SOFTWARE\Microsoft\OLE HKLM\SOFTWARE\Microsoft\RPC HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Language Pack HKCU\SOFTWARE\Classes HKCU\SOFTWARE\Classes\Appid HKCU\SOFTWARE\Classes\CLSID HKCU\SOFTWARE\Classes\DirectShow HKCU\SOFTWARE\Classes\Interface HKCU\SOFTWARE\Classes\Media Type HKCU\SOFTWARE\Classes\MediaFoundation Redirected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected Redirected and reflected Redirected and reflected Redirected Redirected and reflected Redirected and reflected Redirected Redirected Redirected Redirected Redirected Redirected Redirected Redirected Redirected Redirected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected and reflected Redirected Shared Shared Redirected Redirected Redirected Redirected Redirected Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Shared Redirected Redirected Redirected Redirected Redirected
29.11.2012 34
29.11.2012 35
29.11.2012 36
29.11.2012 37
64 Bit 32 Bit "32 Bit" Files "32 Bit" Keys "32 Bit" Values "64 Bit" Files "64 Bit" Keys "64 Bit" Values sees sees
29.11.2012 38
WOW!
29.11.2012 39
29.11.2012 40
29.11.2012 41
29.11.2012 42
29.11.2012 43
M$: Be careful with this – when it's off, it's off!
If you google ... Since Vista there should be 2 new functions
to be used with the according flag KEY_FLAG_DISABLE_REDIRECTION No documentations, not in the API header‐files, no trace at all Rumor?
29.11.2012 44
29.11.2012 45
29.11.2012 46
Questions Feedback Flowers Presents Kisses Hugs Hand‐ shakes Slaps Smalltalks Longtalks Short‐ drinks Longdrinks …
29.11.2012 47
29.11.2012 48
29.11.2012 49
29.11.2012 50