• Home
  • TTP
  • Pages
  • p2.4_net_sockets.mem // Network Forensics: Intercepting the “Phone Home”

In the previous lectures, we captured the memory and hunted down the hidden processes. But a modern malware infection is rarely an isolated event. Most malware acts as a Beacon—it is designed to “Phone Home” to a Command & Control (C2) server to receive instructions, upload stolen data, or download further payloads.

When you have a memory dump, you have a frozen map of every “conversation” the computer was having with the outside world at the moment of the snapshot. In Network Forensics via Memory, we aren’t just looking at traffic; we are looking at the sockets and the resolver cache.


1. The Digital Paper Trail: Network Sockets

A “Socket” is the combination of an IP Address and a Port Number. In the Windows Kernel, these are managed by the tcpip.sys driver.

When an analyst looks at network artifacts in RAM, they are looking for three specific states:

  • LISTENING: The computer is waiting for someone to connect to it. (Example: A hidden backdoor waiting for the attacker).
  • ESTABLISHED: An active, live conversation. (Example: Malware currently exfiltrating your Documents folder to a server in a foreign country).
  • CLOSE_WAIT/TIME_WAIT: The “echo” of a recently closed connection. Even if the attacker disconnected seconds before you took the memory dump, the “ghost” of that connection remains in the kernel structures for a short period.

2. Interrogating the DNS Cache (The Memory of Names)

Before a computer connects to malicious-site.com, it must ask a DNS server for the IP address. Windows stores these answers in the DNS Client Cache to speed up future requests.

  • The Forensic Value: Even if the malware is not currently connected, the DNS cache will prove that the computer tried to talk to a specific domain.
  • TTL (Time to Live): Every entry in the DNS cache has a countdown timer. If you capture the RAM quickly, you can see exactly which malicious domains were resolved in the last few minutes of the system’s life.

3. Tactical Command: windows.netstat

In Volatility 3, the primary tool for this interrogation is the netstat plugin. Unlike the live netstat command (which malware can lie to), the Volatility version scans memory for TCP_ENDPOINT and UDP_ENDPOINT structures.

Execution:

python3 vol.py -f dump.mem windows.netstat

OUTPUT :

What to look for in the output:

  1. Foreign Addresses: Look for IP addresses that don’t belong to your organization. Use “Whois” or “Threat Intelligence” (like VirusTotal) to see if that IP is a known C2 server.
  2. Suspicious Ports:
    • Port 80/443: Standard web traffic (Malware often hides here to look like a browser).
    • Port 4444/5555: Classic default ports for tools like Metasploit.
    • Non-Standard Ports: High-numbered ports (e.g., 59281) used for custom encrypted tunnels.
  3. Owner PID: The most critical column. netstat tells you which Process ID owns the connection. If you see an ESTABLISHED connection to an unknown IP, and the owner is svchost.exe, you must check if that svchost.exe is a legitimate system process or a hollowed-out imposter.

. Advanced Correlation: Sockets to Processes

The true power of Network Forensics in RAM is Correlation.

Imagine you find an ESTABLISHED connection to a suspicious IP on Port 80.

  1. You identify the PID (e.g., 4082).
  2. You go back to windows.psscan and see that PID 4082 is explorer.exe.
  3. The Analysis: Why is explorer.exe (the file browser) talking to a Russian IP address on Port 80? explorer.exe should only be managing your desktop. This is a clear indicator of Code Injection (where the malware is living inside the explorer process).

5. Interactive Lab: [OPERATOR@OCSALY]# vol.py windows.netstat –find-c2

SITUATION: You have the RAM dump from a workstation suspected of a data breach. You need to identify the attacker’s Command & Control IP and determine which process is leaking the data.

YOUR MISSION: Analyze the network table below. Identify the Anomaly.

ProtoLocal AddrForeign AddrStatePIDOwner
TCP192.168.1.10:44352.12.4.1:443ESTABLISHED1204chrome.exe
TCP192.168.1.10:1350.0.0.0:0LISTENING800rpcss.exe
TCP192.168.1.10:590291.24.1.88:443ESTABLISHED3044lsass.exe
TCP127.0.0.1:491520.0.0.0:0LISTENING544wininit.exe
INTEL_ALERT
Connection validated.
VOLATILITY_ACQUISITION // NETSCAN_MODULE
SCANNING_SOCKETS…
LOCAL_IP FOREIGN_IP PORT STATE PID
[READY] Identifying TCP_ENDPOINT structures…

6. Why the Attacker uses lsass.exe

In the lab above, the anomaly is the connection from lsass.exe to 91.24.1.88. lsass.exe (Local Security Authority Subsystem Service) is a critical Windows process responsible for enforcing security policies and handling user logins. It should never initiate a connection to a random IP on the internet.

When you see this, you know the attacker has performed Process Injection or DLL Injection. They are using a trusted system process as a “cloak” to bypass your firewall. Because most firewalls trust lsass.exe to do its job, the malicious traffic is allowed to “Phone Home” without being blocked.