memory forensics memory forensics tools memory forensics volatility memory forensics tutorial memory forensics ppt memory forensics book memory forensics ctf memory forensics pdf memory forensic analysis memory forensic tools memory forensic samples memory forensic software memory forensic tools windows memory forensic analysis pdf memory forensic training memory forensic challenges memory forensic ctf memory forensic analysis tools forensic memory acquisition forensic memory analysis memory dump forensic analysis ram memory forensic analysis volatile memory forensic analysis memory and forensics malware and memory forensics training disk and memory forensics best memory forensic tools memory capture forensic forensic memory capture tools forensic memory card reader eyewitness memory forensic psychology memory forensic examples rekall memory forensic framework rekall memory forensics rekall memory forensic memory forensic imaging eyewitness memory in forensic psychology in-memory forensic memory forensic information memory dump linux forensic linux memory forensic lime memory forensic memory forensic meaning what does memory forensic mean mac memory forensic memory forensic nedir sans memory forensics poster art of memory forensic pdf forensic psychology memory python memory forensic redline memory forensic remote memory forensic memory forensic science sans memory forensic strings memory forensic windows memory forensic toolkit memory dump forensic tools volatility memory forensic tool hyper-v memory forensics forensic memory dump windows 10 forensic memory dump windows windows memory forensic why memory forensic x-ways memory forensics mac os x memory forensics windows 7 memory forensic volatility index volatility meaning in sinhala volatility 10 index volatility 75 index volatility synonym volatility index trading volatility download volatility 10 index live chart volatility of fertilizer volatility meaning volatility adalah volatility arbitrage volatility and vapor pressure volatility and standard deviation volatility adjustment volatility and boiling point volatility antonym volatility analysis volatility and intermolecular forces volatility and variance a volatility meaning a volatility person a volatility drag a volatility model a volatility risk a volatility market volatility a level chemistry volatility a measure of risk volatility a physical property volatility a new normal volatility breakout volatility broker volatility beta volatility black scholes volatility business definition volatility based decomposition volatility bitcoin volatility bands volatility bowling ball volatility boiling point brk.b volatility volatility chemistry volatility calculation volatility clustering volatility cheat sheet volatility chemistry definition volatility contraction pattern volatility calculator excel download volatility curve volatility chart c'est quoi volatility 75 index volatility definition volatility def volatility definition chemistry volatility drag volatility definition economics volatility deutsch volatility download windows volatility dumpfiles volatility derivatives d-limonene volatility r&d volatility drivers r&d volatility super d volatility volatility etf volatility economics volatility excel volatility examples volatility etf list volatility equation volatility extract file from memory volatility etf 3x volatility excel formula volatility economics meaning o que e volatility volatility formula volatility forensics volatility finance volatility forex volatility formula excel volatility forecasting volatility futures volatility finance definition volatility factor volatility for windows f&o volatility f-response volatility f market volatility f&o daily volatility f stock implied volatility volatility github volatility greek volatility graph volatility gui volatility gas volatility greek symbol volatility guide volatility gas chromatography volatility game volatility group 17 volatility halt volatility hedge funds volatility hedge volatility hashdump volatility harvesting volatility halt auction period volatility high volatility handles volatility hunter mt4 volatility hiberfil.sys h-l volatility volatility index 75 volatility index 10 volatility index 75 trading strategies pdf volatility index 75 broker ivolatility ivolatility calculator ivolatility pricing ivolatility data ivolatility charts ivolatility reviews ivolatility vs livevol ivolatility api ivolatility services ivolatility cboe volatility jelentése volatility jumps volatility java volatility jokes volatility json output volatility jobs volatility json volatility jumps the role of geopolitical risks volatility jumps and their economic determinants volatility journal volatility kali volatility kdbgscan volatility kdbg volatility kali install volatility kills reading answers volatility kya hai volatility kali tutorial volatility keepass volatility kills ielts reading answers volatility kills ielts reading k value volatility k minimum volatility quantitative ltf k value relative volatility k china controlled volatility k means clustering volatility k minimum volatility quantitative equity k minimum volatility quantitative equity fund k switzerland low volatility index k china controlled volatility fund volatility linux volatility là gì volatility linux profiles volatility liquid volatility list profiles volatility lab volatility linux commands volatility lietuviskai volatility logged in user volatility log returns volatility l yk p&l volatility l.w. volatility break-out calculate p&l volatility levy driven volatility models l&s volatility index volatility meaning in hindi volatility meaning in english volatility meaning in tamil volatility meaning in urdu volatility meaning in telugu volatility meaning in marathi volatility meaning in malayalam volatility m m-cresol volatility volatility news volatility notepad volatility netscan volatility ne demek volatility nse volatility nasdaq volatility network connections volatility no base address space volatility neutral strategy volatility nederlands volatility and meaning n-hexane volatility n-heptane volatility n-propanol volatility n-methylpyrrolidone volatility n-butyl acetate volatility portfolio volatility n assets volatility of a stock volatility of fuel volatility of volatility volatility options volatility of a portfolio volatility of water volatility of ionic compounds volatility of halogens volatility of ethanol volatility of o volatility smile o market volatility nse f&o volatility return volatility o o-anisidine volatility volatility o que significa o que volatility volatility pronunciation volatility profiles volatility plugins volatility python volatility percentage volatility po polsku volatility program volatility psychology volatility pslist volatility pumping volatility p.a volatility p&l s&p volatility s&p volatility index s&p volatility history s&p volatility 2018 volatility quality zero line volatility quotient volatility quality volatility quality zero line mt4 volatility quality indicator volatility quotient formula volatility quotes volatility quality index volatility quant volatility quizlet infiniti q volatility alpha fund infiniti q volatility alpha infiniti q volatility infiniti q volatility fund volatility risk volatility ratio volatility risk premium volatility refers to volatility rate volatility report nse volatility ratio indicator volatility range volatility ram volatility ratio indicator mt4 r volatility function r volatility calculation r volatility surface r volatility forecast r volatility of returns r volatility with quandl r volatility model r volatility analysis volatility r package volatility r code volatility smile volatility surface volatility skew volatility stocks volatility standard deviation volatility swap volatility software volatility smirk volatility science volatility s&p 500 s&p 500 volatility volatility s&p volatility s&p 500 historical data volatility s&p 500 (^vix) yahoo finance volatility s&p 500 chart volatility s&p index volatility s&p 500 (^vix) google finance volatility trading volatility trading strategies volatility tool volatility trading strategies pdf volatility term structure volatility tutorial volatility thesaurus volatility trading pause volatility targeting volatility training t-bill volatility at&t volatility t implied volatility t distribution volatility t rowe price volatility volatility uncertainty complexity and ambiguity volatility unit volatility usage volatility uncertainty complexity and ambiguity (vuca) volatility ubuntu volatility userassist volatility update volatility user guide volatility used in a sentence volatility uncertainty u.s. low volatility fund (putnam) u.s. minimum volatility etf u.s. managed volatility fund u.s. market volatility volatility vs standard deviation volatility vs variance volatility variance volatility vix volatility vs risk volatility vs boiling point volatility variance or standard deviation volatility vs beta volatility vs implied volatility volatility vs liquidity volatility v risk volatility v instability volatility and solubility vlab volatility hyper-v volatility variance v volatility volatility institute vlab v stochastic volatility výpočet volatility v excelu volatility workbench volatility windows volatility windows 10 volatility wiki volatility windows 10 profile volatility weighted portfolio volatility water volatility windows 10 1903 volatility weighting volatility windows server 2016 profile volatility w volatility xm volatility xls volatility x86 volatility xp volatility xen volatility xau xm volatility index xauusd volatility xiv volatility xylene volatility ledgerx volatility index volatility yarascan volatility yara volatility yahoo finance volatility yield curve volatility yara rules volatility yara plugin volatility youtube volatility yarascan ip address volatility yarascan not working volatility year to month volatility y volatility zerodha volatility z score volatility znaczenie volatility zeus volatility zeus scan volatility znacenje volatility zip password volatility zero volatility zero hedge volatility dmp z spread zero volatility implied volatility z score zero-volatility spread implied volatility 0 implied volatility 0.25 volatility 0.8 volatility 100 index mt5 volatility 10 index mt4 volatility 100 index mt4 volatility 100 index meaning 1 volatility point volatility 1 year volatility 1 standard deviation volatility 1 1-butanol volatility 1 day volatility 1 month volatility ar(1) volatility 1 week volatility 1 hour volatility volatility 25 index volatility 2.6 volatility 25 index live chart volatility 25 volatility 2.6.1 volatility 2020 volatility 2019 volatility 2.7 volatility 2.4 volatility 2 asset portfolio volatility 2 volatility 2 github solvency 2 volatility adjustment glicko 2 volatility ifrs 2 volatility 2-propanol volatility solvency 2 volatility adjustment definition 2-butoxyethanol volatility volatility 3 beta volatility 3 github volatility 3.0 beta volatility 3 commands volatility 3 license volatility 30d volatility 3 release volatility 3 plugins volatility 3.0 download volatility 3x etf 3 volatility stocks volatility 3 download volatility 3 public beta triple 3 volatility advantage fund volatility 411 volatility 401k 401 volatility market volatility 401k volatility rating 4 cboe volatility 411 implied volatility 40 volatility kernel 4.4 volatility of 4-hydroxybenzoic acid metatrader 4 volatility indicator volatility 4 4-nonylphenol volatility 4-hydroxybenzaldehyde volatility volatility 50 index chart volatility 50 index volatility 50 volatility 5.3 5 volatility target hf volatility 50 index volatility sp 500 implied volatility 50 volatility big 5 volatility stoxx 50 5 year volatility 5 year volatility calculation 5 day volatility february 5 volatility 5 min volatility stocks 5 volatility 5 minute realized volatility croci us 5 volatility control croci us 5 volatility control index volatility 64-bit windows volatility 65 volatility 64 bit 65 volatility adjustment 60 volatility implied volatility 68 implied volatility 60 stoxx 600 volatility index stoxx 600 volatility volatility 6 6 month volatility 6/100 historical volatility indicator 6 month implied volatility volatility 75 index mt4 broker volatility 75 index chart tradingview volatility 75 index strategy volatility 75 index strategy pdf volatility 75 index chart volatility 75 index meaning volatility 75 index on xm volatility 75 index signals volatility 75 index strategy pdf download group 7 volatility 7 low-volatility etfs for this roller-coaster market windows 7 volatility profile centos 7 volatility volatility 80 volatility windows 8.1 profile volatility windows 8 volatility windows 8.1 volatility windows 8 profile implied volatility 80 volatility of 8 eb target volatility 8 allianz volatility 8 8-hydroxyquinoline volatility volatility 900 global volatility 90 days volatility 90d bloomberg volatility_90d volatility 99 91 volatility volatility skew 90 110 implied volatility 90 ifrs 9 volatility tc-99 volatility
ඔන්න එහෙනම් පිංවතුනි අපි මල්වාරේ එකක් තනියම හොයන්නේ කොහොමද කියල කියන්න හදන්නේ

ඔව් ඔව් වයිරස් ගාඩ් තියෙද්දී අහවල් එකකටද අපි හොයන්නේ කියල කවුරු හරි හිතනවා ඇති එහෙම හිතන අයයි නැති අයයි මේක ඉවරවෙද්දි තේරුම් ගනී කියල හිතනවා

ඉතින් අපි කලින් දවසක මැෂින් එකේ රැම් එකේ image එකක් ගහගන්න හැටි කතා කලානේ අමතක නම් මේක බලන්න මතක් කරගන්න

ඉතින් අපි අද බලමු කොහොමද ඒ විදිහට ගත්ත ram image එකකින් වයිරස් එකක් වෙන් කරලා අදුරගන්නේ කොහොමද කියල

වැඩි විස්තර නැතුව අපි වැඩේට බහිමු

මේකට ඕනි වෙනවා malware ගියපු කොටින්ම කිව්වොත් වයිරස එකක් ගියපු මසින් එකකින් ගත්ත ram image එකක්

ඉතින් එක අරන් අපේ කාලි මැෂින් එකට කොපි කරගෙන එහෙම ලැස්ති වෙන්නකෝ

ඔය zip එකේ තිබ්බේ ram image එක.
එක මන් extract කරගත්ත

දැන් ටර්මිනල් එක open කරගන්න

හරි දැන් තියෙන්නේ අපි volatility කියන framework එකෙන් තමා ගේම ගහන්න හදන්නේ ඉතින් එක තියනවද බලන්න ඉස්සෙල්ලම , කාලි එකේ නම් කොහොමත් එනවා


හරි තියනව නම් ඔහොම ලස්සනට වැටෙයි

හරි දැන් අපි බලමු මේක මොන os එකකින් ගත්ත ram image එකක්ද කියල, මොකද අපිට හම්බෙන ගොඩක් ඒවා මොකක්ද කියල හරියටම දන්නේ නෑනේ

volatility imageinfo -f cridex.vmem

ඔන්න අපිට බලන්න පුළුවන් ලස්සනට මේ මොන os එකේ ඒවාද කියල

හරි ඉතින් අපි බලමු මේකෙන් කරන්න පුළුවන් වැඩ සෙට් එක

volatility -h

ඔන්න ඔය කමාන්ඩ් එක ගැහුවම කරන්න පුළුවන් වැඩ ටික එනවා

පහල plugin සෙට් එකත් තියනව

හරි දැන් අපි මේ කමාන්ඩ් ටිකක් ගහල බලමු මොනාද හොයාගන්න පුළුවන් කියල

volatility --profile=WinXPSP2x86 -f cridex.vmem pslist

හරි දැන් අපි බැලුවේ ram image එක ගන්න වෙලේ දුව දුව තිබ්බ process වල ලිස්ට් එක

දැන් බලමු එක tree එකක විදිහට

volatility --profile=WinXPSP2x86 -f cridex.vmem pstree

දැන් බලමු මොනාද ඒ වෙලාවේ තිබ්බ connections කියලා

volatility --profile=WinXPSP2x86 -f cridex.vmem connscan

හරි දැන් මම මේකේ process වලට ගත්ත dll ලිස්ට් එක බලල ගන්න හදන්නේ


volatility --profile=WinXPSP2x86 -f cridex.vmem dlllist

හරි දැන් අපි අලුත් folder එකක් හදල dll dump එකක් ගම්මු

mkdir examin

volatility --profile=WinXPSP2x86 -f cridex.vmem dlldump memory -D examin/

හරි දැන් අපි මේකේ malware එකක් තියනවද කියල බලන්න මේ කමාන්ඩ් එක ගහනව

volatility --profile=WinXPSP2x86 -f cridex.vmem malfind -D examin/

දැන් dump එකකුත් ගමු scan කරන්න

volatility --profile=WinXPSP2x86 -f cridex.vmem moddump memory -D examin/

දැන් අපි කාලි එකට එන scanner එකකින් scan කරලා බලමු

clamscan examin/ | grep -v ": OK$"

හරි දැන් මේකෙන් නම් detect උනේ නෑ

ඉතින් අපි කෝකටත් සැක exe file මේ විදිහට extract කරලා virustotal දාල බලමු

මන් දැන් folder එකක් හදල එකට extract කරන්න හදන්නේ

දැන් virustotal ගිහින් අප්ලෝඩ් කරනවා

ඔන්න ඉතින් මේකේ ලිස්ට් එකක් ආව මොන මොන ගාඩ් වලින් ද ඇල්ලුවේ මොනාද කියල

පේනවනේ ඉතින් හැම ගාඩ් එකක්ම හැම වයිරස් එකක්ම අල්ලන්නේ නෑ කියල

මන් හිතනවා කට්ටිය මේකෙන් දෙයක් ගන්න ඇති කියල පට්ටම නිදි මතයි මන් එහෙනම් ගිහින් එන්නම් ජයවේවා හැමෝටම


Manusha Amal

Hi, I am Manusha. Currently working as Systems Engineer. I

Post A Comment:


දිරියක් වෙන්න අදහස් පෙළක් දාන්න