Detecting code injection by cross-validating stack and VAD information in windows physical memory
Anurag Kumar Srivastava, James H. Jones · 2017
Memory forensics involves analysis of the physical memory contents of a computer system to derive information such as the source of a malfunction or malicious activity. Some malicious activity is implemented by injecting code into a running process, which is often undetectable by traditional anti-malware techniques. In this work, we present a method using stack analysis to locate injected code. The execution stack is an essential data structure in process memory and is a source of useful information regarding the execution of code on a computer system. Previous work has focused on using the stack for extracting forensically sensitive information using API analysis. In this work, we demonstrate how stack analysis can detect code injected in process memory, and we provide useful information even when other techniques fail. Our approach can locate injected code when VAD structure nodes have been modified by the malware to remain stealthy, and when the protection of the memory region has been made to appear as normal. We have implemented a plugin using the open source Volatility tool and have tested it on a malware-infected memory image.