Notice
Recent Posts
Recent Comments
Link
ยซ   2025/11   ยป
์ผ ์›” ํ™” ์ˆ˜ ๋ชฉ ๊ธˆ ํ† 
1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30
Tags
more
Archives
Today
Total
๊ด€๋ฆฌ ๋ฉ”๋‰ด

Dev

Cuckoo Sandbox Install: (1) ๋ณธ๋ฌธ

Cyber Security

Cuckoo Sandbox Install: (1)

flutterbylily 2023. 4. 18. 18:06

Cuckoo Sandbox ๊ตฌ์„ฑ

 

๐ŸŒŸ Cuckoo Server

  • OS: Ubuntu 22.04
  • IP: 192.168.159.135 

 

๐ŸŒŸ Sandbox

  • cuckoo1
  • OS: Windows 7 32bit
  • IP: 192.168.56.10

 

 

 

Cuckoo Sandbox ๊ตฌ์ถ• ์ˆœ์„œ:

๐ŸŒŸ ๊ธฐ๋ณธ ํŒจํ‚ค์ง€ ๋ฐ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์„ค์น˜

๐ŸŒŸ cuckoo ์ฝ”์–ด ์„ค์น˜

๐ŸŒŸ sandbox ๊ตฌ์„ฑ

๐ŸŒŸ cuckoo ์›น ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ตฌ์„ฑ

๐ŸŒŸ cuckoo ์„ค์ • ๋ฐ ์‹คํ–‰

 


 

1. ๊ธฐ๋ณธ ํŒจํ‚ค์ง€ ๋ฐ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์„ค์น˜

  • ํŒจํ‚ค์ง€ ๋ฐ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์„ค์น˜ํ•  ์ค€๋น„๋ฅผ ์œ„ํ•ด ์—…๋ฐ์ดํŠธ.
sudo apt-get update

 

 

1) ๊ธฐ๋ณธ ํŒจํ‚ค์ง€ ๋ฐ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์„ค์น˜

 

ํ˜„์žฌ ๋ฒ„์ „ 22.04 ๊ธฐ์ค€์œผ๋กœ ๊ตฌ์ถ•์‹œ python2.7, python3 ํ˜ผ์šฉ ์„ค์น˜ ํ•„์š”.

sudo apt-get install python2.7 python2.7-dev python3 python3-dev python3-pip

 

pip 2๋ฒ„์ „์„ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ๊ณผ ๊ฐ™์€ command:

sudo add-apt-repository universe
sudo apt-get install curl
curl https://bootstrap.pypa.io/pip/2.7/get-pip.py --output get-pip.py
sudo python2.7 get-pip.py

์œ ๋‹ˆ๋ฒ„์Šค ๋ฆฌํฌ์ง€ํ† ๋ฆฌ ํ™œ์„ฑํ™” ํ›„, curl ์Šคํฌ๋ฆฝํŠธ๋กœ ๋‹ค์šด๋กœ๋“œํ•˜์—ฌ pip๋ฅผ ์„ค์น˜.

 

 

๋‚˜๋จธ์ง€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์„ค์น˜ ์ง„ํ–‰:

sudo apt-get install subversion
sudo apt-get install libssl-dev libjpeg-dev zlib1g-dev libffi-dev git
sudo apt-get install automake autoconf libtool build-essential wget swig
sudo apt-get install libpcre3 libpcre3-dev libpcre++-dev -y
sudo apt-get install python3-magic python3-dpkt python3-sqlalchemy python3-jinja2 -y
sudo apt-get install python3-pymongo python3-bottle python3-virtualenv python-setuptools -y

 

 

2) tcpdump

 

  • tcpdump

    ๋„คํŠธ์›Œํฌ ์ƒ ์†ก์ˆ˜์‹ ๋˜๋Š” ํŒจํ‚ท๋“ค์˜ ์ •๋ณด๋“ค์„ ๊ฐ€๋กœ์ฑ„(์Šค๋‹ˆํ•‘) ์ •๋ณด๋“ค์„ ํ‘œ์‹œํ•ด์ฃผ๋Š” ๋„คํŠธ์›Œํฌ ํŒจํ‚ท ์บก์ฒ˜ ๋ฐ ๋ถ„์„๋„๊ตฌ.

    cuckoo sandbox์—์„œ๋Š” ๋ถ„์„ ์ค‘ malware์— ์˜ํ•ด ์ƒ์„ฑ๋œ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์„ ์บก์ฒ˜ํ•˜๊ณ  ๋ถ„์„ํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์ œ๊ณต.

 

 

๋‹ค์Œ command๋ฅผ ํ†ตํ•ด tcpdump์™€ apparmor-utils ์„ค์น˜:

sudo apt-get install tcpdump apparmor-utils

 

app armor๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ณ , tcpdump๋ฅผ root ๊ถŒํ•œ ์—†์ด ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ์„ค์ •:

sudo aa-disable /usr/bin/tcpdump
sudo setcap cap_net_raw,cap_net_admin=eip /usr/bin/tcpdump

โ€ป tcpdump issue : https://jihyun-dev.tistory.com/4 

 

tcpdump directory issue: /usr/sbin/tcpdump

๋‚˜๊ฐ™์€ ๊ฒฝ์šฐ์—๋Š” cuckoo sandbox๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด tcpdump๊ฐ€ ํ•„์š”ํ–ˆ๊ณ ... ๋‹ค๋ฅธ ์ด์œ ๋กœ๋„ tcpdump๊ฐ€ ํ•„์š”ํ•œ ๋ถ„๋“ค์ด ์žˆ๊ฒ ์ง€๋งŒ ์•„๋ฌดํŠผ ์ตœ์‹  ๋ฒ„์ „์˜ ๋ฌธ์ œ์ธ์ง€ ๋ชฐ๋ผ๋„ ๊ณ„์† ์—๋Ÿฌ ๋ฐœ์ƒ. ๊ทผ๋ฐ ์–ด์ฉ์ง€ ๊ทธ ์—๋Ÿฌ๋“ค

jihyun-dev.tistory.com

 

 

3) ssdeep, pydeep

 

(1) ssdeep ์„ค์น˜

 

  • ssdeep

    Fuzzy Hash๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์›๋ณธ ํŒŒ์ผ๊ณผ ์œ ์‚ฌ๋„ ์ธก์ •, Hash ๊ฐ’์„ ํ†ตํ•ด ๋ฌด๊ฒฐ์„ฑ ์ฒดํฌ.

    sandbox์— submit๋œ ํŒŒ์ผ์˜ Hash๊ฐ’์„ ํ†ตํ•ด malware์˜ ๋ณ€์ข…์ธ์ง€ ๋น„๊ตํ•˜๋Š”๋ฐ ์‚ฌ์šฉ, ๊ด€๋ จ์žˆ๋Š” ํŒŒ์ผ์„ ๋น ๋ฅด๊ฒŒ ์‹๋ณ„.

    

 

๋‹ค์Œ command๋ฅผ ํ†ตํ•ด ssdeep.tar.gz ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ๋ฐ ์••์ถ•ํ•ด์ œ:

wget http://sourceforge.net/projects/ssdeep/files/ssdeep-2.13/ssdeep-2.13.tar.gz
tar zxf ssdeep-2.13.tar.gz
rm -r ssdeep-2.13.tar.gz
mv ssdeep-2.13 ssdeep

 

ssdeep ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ์ด๋™ํ•˜์—ฌ ์„ค์ •:

cd ssdeep
./configure && make && make install
sudo ldconfig

 

 

(2) pydeep

 

  • pydeep

    cuckoo sandbox์— ์žˆ์–ด์„œ pydeep์€ Fuzzy Hashing์„ ์ˆ˜ํ–‰, ํŒŒ์ผ์„ cuckoo sandbox์— submitํ•˜๋ฉด pydeep์ด

    ํ•ด๋‹น ํŒŒ์ผ์— ๋Œ€ํ•œ CTPH Hash๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ์•Œ๋ ค์ง„ Hash ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์™€ ๋น„๊ตํ•˜์—ฌ ๋ถ„์„ ์ง„ํ–‰.

    ์ฆ‰, ์ž ์žฌ์ ์œผ๋กœ ์•…์„ฑ์ผ ํŒŒ์ผ์„ ํšจ์œจ์ ์œผ๋กœ ๋ถ„์„ ๋ฐ ์‹๋ณ„ ๊ฐ€๋Šฅ.

 

 

๋‹ค์Œ command๋ฅผ ํ†ตํ•ด pydeep ์„ค์น˜:

git clone https://github.com/kbandla/pydeep.git pydeep
cd pydeep
sudo apt-get install libfuzzy-dev
python3 setup.py build
sudo python3 setup.py install

 

 

4) pefile

 

  • pefile

    ์‹คํ–‰ํŒŒ์ผ(.exe), DLL ๋ฐ ๊ธฐํƒ€ ๋ฐ”์ด๋„ˆ๋ฆฌ ํŒŒ์ผ์— ์‚ฌ์šฉํ•˜๋Š” ํŒŒ์ผ ํ˜•์‹์ธ PE(Portable Executable)ํŒŒ์ผ์— ์ž‘์—…ํ•˜๋Š”

    Python ๋ชจ๋“ˆ. malware ๋ถ„์„์—์„œ PEํŒŒ์ผ์˜ ์ •๋ณด ์ถ”์ถœ์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ถ”์ถœ ์ •๋ณด๋Š” ์ฃผ๋กœ ํŒŒ์ผ์˜ ๋ชฉ์ , malware ์—ฌ๋ถ€, 

    ์‹คํ–‰ ์‹œ ์–ด๋–ค ๋™์ž‘์„ ๋ณด์ด๋Š”์ง€ ํŒŒ์•…ํ•˜๋Š”๋ฐ ์‚ฌ์šฉ.

 

 

๋‹ค์Œ command๋ฅผ ํ†ตํ•ด PE file ๋‹ค์šด๋กœ๋“œ:

wget https://github.com/erocarrera/pefile/releases/download/v2023.2.7/pefile-2023.2.7.tar.gz
tar zxf pefile-2023.2.7.tar.gz
rm -r pefile-2023.2.7.tar.gz
mv pefile-2023.2.7 pefile

 

pefile ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ์ด๋™ํ•˜์—ฌ ์„ค์น˜:

cd pefile
python3 setup.py build
sudo python3 setup.py install

 

 

 

5) yara

 

  • yara

    malware ํŒจํ„ด ๋งค์นญ ๋ฐ ํƒ์ง€์— ์‚ฌ์šฉ. ํŠน์ • malware์˜ ๋™์ž‘์ด๋‚˜ ํŠน์„ฑ์„ ์‹๋ณ„ํ•˜๊ธฐ ์œ„ํ•ด yara rule์„ ์ƒ์„ฑํ•˜๊ณ 

    ์ด rule์„ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ, ๋ฉ”๋ชจ๋ฆฌ์—์„œ ์ž ์žฌ์ ์ธ malware๋ฅผ ๊ฒ€์‚ฌ ๊ฐ€๋Šฅ(Signature ๊ธฐ๋ฐ˜ ํƒ์ง€)

 

 

yara-4.3.0.tar.gz ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ:

wget https://github.com/VirusTotal/yara/archive/refs/tags/v4.3.0.tar.gz
tar zxf v4.3.0.tar.gz
rm -r v4.3.0.tar.gz
mv yara-4.3.0 yara

 

yara ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ์ด๋™, ์„ค์น˜ ๋ฐ ์„ค์ • ์™„๋ฃŒ:

cd yara
sudo apt-get install libtool*
./bootstrap.sh
./configure
make
sudo make install

 

yara๋ฅผ python์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ๋‹ค์Œ command๋ฅผ ํ†ตํ•ด yara-python ์„ค์น˜:

git clone --recursive https://github.com/VirusTotal/yara-python
cd yara-python
python3 setup.py build
sudo python3 setup.py install

 

6) m2crypto

 

  • m2crypto

     ์•”ํ˜ธํ™”, ์•”ํ˜ธ ํ•ด๋… ๋ฐ ๋””์ง€ํ„ธ ์„œ๋ช… ๋“ฑ ์•”ํ˜ธํ™” ๊ธฐ๋Šฅ์— ์‚ฌ์šฉ๋˜๋Š” Python ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ.

     SSL/TLS ์•”ํ˜ธํ™” ๋ฐ ๋””์ง€ํ„ธ ์ธ์ฆ์„œ ๊ด€๋ฆฌ์™€ ๊ฐ™์€ ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์‚ฌ์šฉ.

 

 

๋‹ค์Œ command๋ฅผ ํ†ตํ•ด m2crypto๋ฅผ ์„ค์น˜:

sudo pip install m2crypto

 

 

7) Volatility

 

  • Volatility

    ๋ฉ”๋ชจ๋ฆฌ ๋คํ”„์—์„œ malware๋‚˜ ํ•ดํ‚น, ๊ธฐํƒ€ ๋ณด์•ˆ ์‚ฌ๊ณ  ์ฆ๊ฑฐ๋ฅผ ๋ถ„์„ํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ฉ”๋ชจ๋ฆฌ ํฌ๋ Œ์‹ ๋„๊ตฌ.

    ์‹คํ–‰ ์ค‘์ธ ํ”„๋กœ์„ธ์Šค, ๊ฐœ๋ฐฉํ˜• ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ๋ฐ ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ๋‚˜ํƒ€๋‚ผ ์ˆ˜ ์žˆ๋Š” ๊ธฐํƒ€ ์‹œ์Šคํ…œ ํ™œ๋™์— ๋Œ€ํ•œ ์ •๋ณด ์ถ”์ถœํ•˜๋Š”๋ฐ

    ์‚ฌ์šฉ.

 

 

volatility๋ฅผ git clone์œผ๋กœ ๋ณต์ œํ•˜์—ฌ ๋ฐ›์•„์˜ค๊ณ  ํ•ด๋‹น ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ์ด๋™ ๋ฐ ์„ค์น˜:

sudo git clone https://github.com/volatilityfoundation/volatility.git
cd volatility
python3 setup.py build
sudo python3 setup.py install

 

 

  • distorm3

    ๋ฆฌ๋ฒ„์Šค ์—”์ง€๋‹ˆ์–ด๋ง ๋ฐ malware ๋ถ„์„์— ์‚ฌ์šฉ. ์‹คํ–‰ ์ฝ”๋“œ๋ฅผ ์–ด์…ˆ๋ธ”๋ฆฌ ์–ธ์–ด๋กœ ๋””์Šค์–ด์…ˆ๋ธ”ํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋””์Šค์–ด์…ˆ๋ธ”๋Ÿฌ

    ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋กœ, ํ”„๋กœ๊ทธ๋žจ์˜ ์ž‘๋™ ๋ฐฉ์‹๊ณผ ๊ธฐ๋Šฅ์„ ํŒŒ์•…ํ•˜๋Š”๋ฐ ์ด์šฉ.

 

 

distorm3์„ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ• ํ•ด์ œ:

sudo apt-get install libboost-all-dev
wget https://github.com/gdabah/distorm/archive/v3.4.4.tar.gz
tar zxvf v3.4.4.tar.gz
sudo rm -r v3.4.4.tar.gz
mv distorm-3.4.4 distorm3

 

distorm3 ๋””๋ ‰ํ„ฐ๋ฆฌ๋กœ ์ด๋™ ํ›„ ์„ค์น˜:

cd distorm3
sudo python3 setup.py build
sudo python3 setup.py install

 

 

'Cyber Security' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

Cuckoo Sandbox: Unable to stop auxiliary module: Sniffer  (0) 2023.07.21
Cuckoo Sandbox Install: (3)  (0) 2023.04.24
Cuckoo Sandbox Install: (2)  (0) 2023.04.24
tcpdump directory issue: /usr/sbin/tcpdump  (0) 2023.03.02
yara์™€ yara์˜ ๋Œ€์ฒด๋ฅผ ์ฐพ์•„์„œ(1)  (0) 2023.02.12