{"id":995,"date":"2012-05-31T20:08:01","date_gmt":"2012-05-31T20:08:01","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=995"},"modified":"2018-12-15T00:52:01","modified_gmt":"2018-12-15T00:52:01","slug":"mft-scanning-for-fun-and-err-flame","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2012\/05\/31\/mft-scanning-for-fun-and-err-flame\/","title":{"rendered":"$MFT scanning for fun and err&#8230; Flame"},"content":{"rendered":"<p><strong>Update 2018-12-15<\/strong><\/p>\n<p>This tool was an experiment; please do not use it anymore as it produces unreliable reports; the tool has not been updated for many years. Use modern AV\/EDR software instead. Thanks!<\/p>\n<p><strong>Update 2012-July<\/strong><\/p>\n<p>Expect this tool to grow over next couple of months.<\/p>\n<p><strong>Old Post<\/strong><\/p>\n<p>I was toying around with $MFT parsing and came up with a simple demo tool that parses $MFT looking for remnants of malware. Tool is written in x86 assembly so I guess it is forensically sound \ud83d\ude09<\/p>\n<p>At the moment it only scans for flame malware (I used list from all the places I could find including my own research, CrySyS Lab, Kaspersky, BitDefender, malware.lu, kernelmode.info, etc. &#8211;\u00a0 list pasted below).<\/p>\n<p>It should find entries that are both live (existing files) and deleted entries.<\/p>\n<p>This is how it works &#8211; if it is bad news for you:<\/p>\n<p><a href=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2012\/05\/hcd_flame.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-996\" title=\"hcd_flame\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2012\/05\/hcd_flame-300x203.png\" alt=\"\" width=\"300\" height=\"203\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2012\/05\/hcd_flame-300x203.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2012\/05\/hcd_flame.png 714w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Note: this is an experimental tool &#8211; DO NOT test it on production system. You can always use fls.exe from sleuthkit.<\/p>\n<p>The tool can be downloaded <a href=\"https:\/\/hexacorn.com\/download.php?f=hcd.exe\">here<\/a>.<\/p>\n<p>This is a list of files it searches for:<\/p>\n<ul>\n<li>advnetcfg.ocx<\/li>\n<li>Advpck.dat<\/li>\n<li>audache<\/li>\n<li>audfilter.dat<\/li>\n<li>authcfg.dat<\/li>\n<li>authpack.ocx<\/li>\n<li>boot32drv.sys<\/li>\n<li>browse32.ocx<\/li>\n<li>ccalc32.sys<\/li>\n<li>cmutlcfg.ocx<\/li>\n<li>commgr32<\/li>\n<li>comspol32.dll<\/li>\n<li>comspol32.ocx<\/li>\n<li>contents.btr<\/li>\n<li>ctrllist.dat<\/li>\n<li>dcomm.dat<\/li>\n<li>desc.ini<\/li>\n<li>dmmsapi.dat<\/li>\n<li>dsmgr.ocx<\/li>\n<li>dstrlog.dat<\/li>\n<li>Ef_trace.log<\/li>\n<li>fib32.bat<\/li>\n<li>frog.bat<\/li>\n<li>gppref32.exe<\/li>\n<li>grb9m2.bat<\/li>\n<li>guninst32<\/li>\n<li>indsvc32.ocx<\/li>\n<li>lib.ocx<\/li>\n<li>lmcache.dat<\/li>\n<li>lss.ocx<\/li>\n<li>m4aaux.dat<\/li>\n<li>modevga.com<\/li>\n<li>mprhlp<\/li>\n<li>MSAPackages<\/li>\n<li>MSAudio<\/li>\n<li>MSAuthCtrl<\/li>\n<li>mscrypt.dat<\/li>\n<li>msglu32.ocx<\/li>\n<li>mssecmgr.ocx<\/li>\n<li>MSSecurityMgr<\/li>\n<li>MSSndMix<\/li>\n<li>mssui.drv<\/li>\n<li>mssvc32.ocx<\/li>\n<li>netcfgi.ocx<\/li>\n<li>ntaps.dat<\/li>\n<li>nteps32<\/li>\n<li>nteps32.ocx<\/li>\n<li>Pcldrvx.ocx<\/li>\n<li>rdcvlt32.exe<\/li>\n<li>Rpcnc.dat<\/li>\n<li>rpcns4.ocx<\/li>\n<li>scaud32.exe<\/li>\n<li>scsec32.exe<\/li>\n<li>sdclt32.exe<\/li>\n<li>secindex.dat<\/li>\n<li>soapr32.ocx<\/li>\n<li>ssitable<\/li>\n<li>stamn32<\/li>\n<li>svchost1ex.mof<\/li>\n<li>Svchostevt.mof<\/li>\n<li>target.lnk<\/li>\n<li>to961.tmp<\/li>\n<li>urpd.ocx<\/li>\n<li>watchxb.sys<\/li>\n<li>wavesup3.drv<\/li>\n<li>winconf32.ocx<\/li>\n<li>winrt32.dll<\/li>\n<li>winrt32.ocx<\/li>\n<li>wlndh32<\/li>\n<li>Wpab32.bat<\/li>\n<li>wpgfilter.dat<\/li>\n<li>wrm3f0<\/li>\n<li>zff042<\/li>\n<li>~8C5FF6C.tmp<\/li>\n<li>~a29.tmp<\/li>\n<li>~d43a37b.tmp<\/li>\n<li>~DEB83C.tmp<\/li>\n<li>~DEB93D.tmp<\/li>\n<li>~DF05AC8.tmp<\/li>\n<li>~dfc855.tmp<\/li>\n<li>~DFD85D3.tmp<\/li>\n<li>~DFL*.tmp<\/li>\n<li>~DFL983.tmp<\/li>\n<li>~dra*.tmp<\/li>\n<li>~dra52.tmp<\/li>\n<li>~dra53.tmp<\/li>\n<li>~f28.tmp<\/li>\n<li>~fghz.tmp<\/li>\n<li>~HLV<\/li>\n<li>~HLV*.tmp<\/li>\n<li>~KWI<\/li>\n<li>~KWI988.tmp<\/li>\n<li>~KWI989.tmp<\/li>\n<li>~mso2a0.tmp<\/li>\n<li>~mso2a1.tmp<\/li>\n<li>~mso2a2.tmp<\/li>\n<li>~nms534<\/li>\n<li>~rcf0<\/li>\n<li>~rcj0<\/li>\n<li>~rei524.tmp<\/li>\n<li>~rei525.tmp<\/li>\n<li>~rf288.tmp<\/li>\n<li>~rft374.tmp<\/li>\n<li>~TFL848.tmp<\/li>\n<li>~TFL849.tmp<\/li>\n<li>~ZLM0D1.ocx<\/li>\n<li>~ZLM0D2.ocx<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Update 2018-12-15 This tool was an experiment; please do not use it anymore as it produces unreliable reports; the tool has not been updated for many years. Use modern AV\/EDR software instead. Thanks! Update 2012-July Expect this tool to grow &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2012\/05\/31\/mft-scanning-for-fun-and-err-flame\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[15,19,24,9,5],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/995"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=995"}],"version-history":[{"count":7,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/995\/revisions"}],"predecessor-version":[{"id":5674,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/995\/revisions\/5674"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}