How Windows Malware Uses COM—and How Analysts Can Analyze It

· Original article ↗

Summary

Talos explains how Windows malware uses COM for functions such as persistence, execution, and data transfer, and shows how analysts can identify COM classes, interfaces, and methods in binaries.

Key points

  • Malware uses COM to access Windows functionality for persistence, execution, system discovery, file transfer, and other activity; DCOM can extend object access across a network.
  • COM activity can be obscured by GUIDs and indirect vtable calls, making class, interface, and method identification useful in binary analysis.
  • Analysts can map CLSIDs and IIDs using registry data and tools such as OleView.NET, ComView, and IDA’s COM Helper, then apply interface types to clarify indirect calls.
  • Talos illustrates the workflow with Qakbot’s use of WMI, Gh0stRAT’s scheduled-task creation, Attor’s BITS transfers, and WarmCookie’s Task Scheduler persistence.
  • YARA hunting can search for COM GUIDs and related APIs, but rules need additional context because they may also match legitimate software.
  • COM activity may not appear as an obvious command-line process launch, so analysts can use static analysis or runtime tracing to investigate it.

Article Details

Topic
Malware abuse of Windows COM and DCOM interfaces and practical reverse-engineering methods for identifying COM functionality

MITRE ATT&CK

People

Malware

Vendors

Products

Tools

Binary Ninjaplugin, and Airbus CERT’s COMIDA and Frank Boldewin’s COM Code Helper scripts are also useful options. Binary Ninja users can apply similar type reconstruction workflows to make interface pointers and vtable callsCOM Code Helperprocess. IDA includes a default COM Helper plugin, and Airbus CERT’s COMIDA and Frank Boldewin’s COM Code Helper scripts are also useful options. Binary Ninja users can apply similar type reconstruction workflowsCOM Helperreverse-engineering tool that maps GUIDs to human-readable code. For example, in IDA Pro, the standard COM Helper can identify relevant class and interface IDs and rename locations in the database.  COMIDAand scripts can accelerate this process. IDA includes a default COM Helper plugin, and Airbus CERT’s COMIDA and Frank Boldewin’s COM Code Helper scripts are also useful options. Binary Ninja users can applyCOMpanionto make interface pointers and vtable calls easier to read. Recent Binary Ninja releases include COMpanion-related data rendering support. ComViewby malware and understanding interfaces together with functions present in their vtables. Tools such as ComView and OleView.NET allow researchers to inspect classes, interfaces, type libraries, proxy/stub information,DispatchLogger For dynamic analysis, tracing can help by observing COM activation and dispatch calls at runtime. DispatchLogger, written by Talos’ David Zimmer, is one example of a DLL that can be injected into a process to proxyDynamoRIOthe analysis environment to help with the mapping. Dynamic binary instrumentation frameworks such as DynamoRIO can also be used for runtime tracing of COM behaviors. IDA Prouse a plugin for your reverse-engineering tool that maps GUIDs to human-readable code. For example, in IDA Pro, the standard COM Helper can identify relevant class and interface IDs and rename locations in theOleView.NETunderstanding interfaces together with functions present in their vtables. Tools such as ComView and OleView.NET allow researchers to inspect classes, interfaces, type libraries, proxy/stub information, and methodTorkeylogging, clipboard capture, file collection and upload, process/window monitoring, persistence, Tor-based C2 communications, and GSM/GPRS device fingerprinting through AT commands. YARA A simplified YARA hunting rule for binaries that reference the Task Scheduler COM class and interface might look like: 

Related Articles