From fe2b2ccaeb075d2c83d7f1bc8ae9fa0bb870ed68 Mon Sep 17 00:00:00 2001 From: AsafEitani Date: Fri, 28 Aug 2020 18:31:28 +0300 Subject: [PATCH] moved vad_dump to vadinfo --- .../framework/plugins/windows/malfind.py | 41 +----------- .../framework/plugins/windows/vadinfo.py | 64 +++++++++++-------- 2 files changed, 40 insertions(+), 65 deletions(-) diff --git a/volatility/framework/plugins/windows/malfind.py b/volatility/framework/plugins/windows/malfind.py index 5ce816bcb..d1ccd7242 100644 --- a/volatility/framework/plugins/windows/malfind.py +++ b/volatility/framework/plugins/windows/malfind.py @@ -33,8 +33,8 @@ class Malfind(interfaces.plugins.PluginInterface): description="Extract injected VADs", default=False, optional=True), - requirements.PluginRequirement(name='pslist', plugin=pslist.PsList, version=(1, 0, 0)), - requirements.PluginRequirement(name='vadinfo', plugin=vadinfo.VadInfo, version=(1, 0, 0)), + requirements.VersionRequirement(name='pslist', component=pslist.PsList, version=(1, 1, 0)), + requirements.VersionRequirement(name='vadinfo', component=vadinfo.VadInfo, version=(1, 1, 0)) ] @classmethod @@ -66,42 +66,7 @@ class Malfind(interfaces.plugins.PluginInterface): return True - @classmethod - def vad_dump(cls, context: interfaces.context.ContextInterface, proc: interfaces.objects.ObjectInterface, vad)\ - -> interfaces.plugins.FileInterface: - """Extracts the memory regions for a process that may contain injected for a process as a FileInterface - code. - Args: - context: The context to retrieve required elements (layers, symbol tables) from - proc: an _EPROCESS instance - vad: The suspected VAD to extract - - Returns: - A FileInterface object containing the complete data for the process or None in the case of failure - """ - proc_id = "Unknown" - try: - proc_id = proc.UniqueProcessId - proc_layer_name = proc.add_process_layer() - except exceptions.InvalidAddressException as excp: - vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, - excp.layer_name)) - return - - proc_layer = context.layers[proc_layer_name] - vad_start = vad.get_start() - - try: - filedata = interfaces.plugins.FileInterface("pid.{0}.{1:#x}.dmp".format(proc.UniqueProcessId, - vad_start)) - filedata.data.write(proc_layer.read(vad_start, vad.get_end() - vad_start, pad=True)) - - except Exception as excp: - vollog.debug("Unable to dump PE with pid {0}.{1:#x}: {2}".format(proc.UniqueProcessId, vad_start, excp)) - return - - return filedata @classmethod def list_injections( @@ -168,7 +133,7 @@ class Malfind(interfaces.plugins.PluginInterface): dumped = False if self.config['dump']: - filedata = self.vad_dump(self.context, proc, vad) + filedata = vadinfo.VadInfo.vad_dump(self.context, proc, vad) if filedata: try: self.produce_file(filedata) diff --git a/volatility/framework/plugins/windows/vadinfo.py b/volatility/framework/plugins/windows/vadinfo.py index a98051133..132401988 100644 --- a/volatility/framework/plugins/windows/vadinfo.py +++ b/volatility/framework/plugins/windows/vadinfo.py @@ -5,7 +5,7 @@ import logging from typing import Callable, List, Generator, Iterable -from volatility.framework import renderers, interfaces +from volatility.framework import renderers, interfaces, exceptions from volatility.framework.configuration import requirements from volatility.framework.objects import utility from volatility.framework.renderers import format_hints @@ -101,34 +101,48 @@ class VadInfo(interfaces.plugins.PluginInterface): yield vad @classmethod - def vad_dump(cls, context: interfaces.context.ContextInterface, layer_name: str, - vad: interfaces.objects.ObjectInterface) -> bytes: - """Extracts the complete data for Vad as a FileInterface + def vad_dump(cls, context: interfaces.context.ContextInterface, proc: interfaces.objects.ObjectInterface, + vad: interfaces.objects.ObjectInterface) -> interfaces.plugins.FileInterface: + """Extracts the complete data for Vad as a FileInterface. Args: - context: the context to operate upon - layer_name: the name of the layer that the VAD lives within - vad: the virtual address descriptor to be dumped + context: The context to retrieve required elements (layers, symbol tables) from + proc: an _EPROCESS instance + vad: The suspected VAD to extract (ObjectInterface) Returns: - bytes containing the data from the vad + A FileInterface object containing the complete data for the process or None in the case of failure """ + proc_id = "Unknown" + try: + proc_id = proc.UniqueProcessId + proc_layer_name = proc.add_process_layer() + except exceptions.InvalidAddressException as excp: + vollog.debug("Process {}: invalid address {} in layer {}".format(proc_id, excp.invalid_address, + excp.layer_name)) + return - tmp_data = b"" - proc_layer = context.layers[layer_name] - chunk_size = 1024 * 1024 * 10 - offset = vad.get_start() - out_of_range = vad.get_end() - # print("walking from {:x} to {:x} | {:x}".format(offset, out_of_range, out_of_range-offset)) - while offset < out_of_range: - to_read = min(chunk_size, out_of_range - offset) - data = proc_layer.read(offset, to_read, pad = True) - if not data: - break - tmp_data += data - offset += to_read + proc_layer = context.layers[proc_layer_name] + vad_start = vad.get_start() + vad_end = vad.get_end() + file_name = "pid.{0}.vad.{1:#x}-{2:#x}.dmp".format(proc_id, vad_start, vad_end) + try: + filedata = interfaces.plugins.FileInterface(file_name) + chunk_size = 1024 * 1024 * 10 + offset = vad_start + while offset < vad_end: + to_read = min(chunk_size, vad_end - offset) + data = proc_layer.read(offset, to_read, pad=True) + if not data: + break + filedata.data.write(data) + offset += to_read - return tmp_data + except Exception as excp: + vollog.debug("Unable to dump VAD {}: {}".format(file_name, excp)) + return + + return filedata def _generator(self, procs): @@ -145,16 +159,12 @@ class VadInfo(interfaces.plugins.PluginInterface): for proc in procs: process_name = utility.array_to_string(proc.ImageFileName) - proc_layer_name = proc.add_process_layer() for vad in self.list_vads(proc, filter_func = filter_func): dumped = False if self.config['dump']: - data = self.vad_dump(self.context, proc_layer_name, vad) - filedata = interfaces.plugins.FileInterface("pid.{0}.vad.{1:#x}-{2:#x}.dmp".format( - proc.UniqueProcessId, vad.get_start(), vad.get_end())) - filedata.data.write(data) + filedata = self.vad_dump(self.context, proc, vad) self.produce_file(filedata) dumped = True