Network and Cyber SecurityUnit 914 min read
Malware Analysis: Types, Behavior, Detection & Reverse Engineering
Unit 9 of Network and Cyber Security explores malware analysis techniques—how to classify, dissect, and mitigate malicious software threats like viruses, ransomware, and spyware. This note covers malware anatomy, static/dynamic analysis methods, reverse engineering basics, and real-world attack case studies (e.g., Emot
Malware: Definition and Classification
Malware (malicious software) is any program or code designed to harm, exploit, or infiltrate computer systems without user consent. It exploits vulnerabilities in software, operating systems, or human behavior to gain unauthorized access or damage data.
Types of Malware
Malware can be classified based on its behavior, propagation method, and intent. Below is a structured classification with examples:
Key Characteristics of Malware
| Feature | Description |
|---|---|
| Propagation | Spreads via email attachments, infected USB drives, or network exploits. |
| Payload | The malicious action (e.g., data theft, system damage, or unauthorized access). |
| Stealth | Uses techniques like polymorphism or encryption to evade detection. |
| Persistence | Installs itself to run automatically (e.g., startup entries, scheduled tasks). |
In the Real World
LockBit Ransomware (Global)
- How it uses malware analysis concepts: LockBit is a ransomware-as-a-service (RaaS) that encrypts victim data and demands Bitcoin payments. Security researchers analyze its behavioral patterns (e.g., lateral movement in networks) and static code (e.g., strings like
LockBit2.0) to develop decryption tools. Companies like Ncell or NTC in Nepal must monitor for such attacks via intrusion detection systems (IDS). - Real-world impact: In 2023, LockBit targeted hospitals in Europe, disrupting patient care. Analyzing its command-and-control (C2) communication helps block attacks.
- How it uses malware analysis concepts: LockBit is a ransomware-as-a-service (RaaS) that encrypts victim data and demands Bitcoin payments. Security researchers analyze its behavioral patterns (e.g., lateral movement in networks) and static code (e.g., strings like
Emotet Trojan (Nepalese Banks)
- How it uses malware analysis: Emotet spreads via phishing emails with malicious Word/Excel macros. Banks like Nabil Bank or Global IME analyze its packed executable (using tools like PEiD or Ghidra) to reverse-engineer its C2 server communication. Dynamic analysis (e.g., Wireshark) reveals its keylogging and credential-stealing behavior.
- Worked example: If a bank employee opens an infected Excel file, Emotet drops a Trojan dropper, which then downloads the full payload. Analyzing the network traffic during infection helps detect similar attacks.
Android Spyware in Mobile Banking Apps (eSewa, Khalti)
- How it uses malware analysis: Fake banking apps (e.g., Fake Khalti) contain spyware that logs keystrokes and steals OTPs. Security firms use static analysis (e.g., AndroGuard) to decompile the APK and identify hardcoded C2 servers. Dynamic analysis on a sandboxed device captures the malware’s data exfiltration to malicious servers.
- Real-world impact: In 2022, a spyware campaign targeted Nepali users via fake eSewa update links, stealing ₹100M+ in transactions.
Malware Analysis Techniques
Malware analysis is divided into two primary methods: static and dynamic.
1. Static Analysis
Static analysis involves examining malware without executing it. This is safer and often used for initial triage.
Key Static Analysis Methods
- File Header Analysis: Inspecting the Magic Numbers (e.g.,
MZfor PE files,PDFfor PDFs) to identify file types.
- String Analysis: Extracting readable text (e.g., URLs, registry keys) using tools like strings or PEiD.
- Packer Detection: Identifying if malware is packed (compressed) using tools like Detect It Easy (DIE).
- Why it matters: Packed malware evades signature-based antivirus (AV) scans.
- Yara Rules: Writing custom rules to detect malware families.
rule LockBitFamily { meta: description = "Detects LockBit ransomware" author = "Nepal Cyber Security Team" strings: $s1 = "LockBit2.0" $s2 = "!@#$%^&*()" condition: all of them }
Tools for Static Analysis
| Tool | Purpose | Example Use Case |
|---|---|---|
| PEiD | Detects packers (e.g., UPX, MPRESS) | Identify if malware is obfuscated. |
| Ghidra | Reverse engineering (disassembly) | Analyze malicious functions in an executable. |
| YARA | Custom malware detection rules | Hunt for LockBit in a network. |
| ExifTool | Extract metadata from files | Check for hidden C2 URLs in images. |
2. Dynamic Analysis
Dynamic analysis involves running malware in a controlled environment (e.g., sandbox) to observe its behavior.
Key Dynamic Analysis Methods
- Sandboxing: Running malware in an isolated VM (e.g., Cuckoo Sandbox, Joe Sandbox).
- Behavioral Monitoring:
- Process Injection: Malware injects code into legitimate processes (e.g.,
svchost.exe). - Network Traffic Analysis: Capturing C2 communication (e.g., DNS tunneling, HTTP POST requests).
- File System Changes: Detecting data encryption (ransomware) or file deletion (wipers).
- Process Injection: Malware injects code into legitimate processes (e.g.,
- Debugging: Using x64dbg or OllyDbg to step through malicious code.
Tools for Dynamic Analysis
| Tool | Purpose | Example Use Case |
|---|---|---|
| Cuckoo Sandbox | Automated malware analysis | Generate reports on new malware samples. |
| Wireshark | Network traffic analysis | Detect C2 server communication. |
| Process Hacker | Monitor running processes | Identify suspicious child processes. |
| RegShot | Compare registry before/after infection | Find malicious registry keys. |
Reverse Engineering Malware
Reverse engineering involves disassembling and analyzing malware code to understand its functionality.
Steps in Reverse Engineering
- Disassembly: Convert binary to assembly (e.g., using Ghidra or IDA Pro).
- Decompilation: Convert assembly to high-level pseudocode (e.g., Ghidra’s decompiler).
- Function Analysis:
- Identify cryptographic functions (e.g., AES encryption in ransomware).
- Find hardcoded keys or C2 server IPs.
- Patch or Decrypt:
- Modify malware to prevent execution (e.g., patching a
jmpinstruction). - Extract decryption keys to recover encrypted files.
- Modify malware to prevent execution (e.g., patching a
Real-World Example: Analyzing a Ransomware Sample
Scenario: A Nepali university’s server is infected with WannaCry ransomware. Security analysts need to reverse-engineer it to develop a decryption tool.
- Static Analysis:
- Use PEiD to confirm it’s a Windows PE executable.
- Extract strings to find the encryption key (
0x1234ABCD).
- Dynamic Analysis:
- Run in Cuckoo Sandbox to observe:
- File encryption (
.txt→.txt.wcry). - Network call to
8.8.8.8(WannaCry’s C2).
- File encryption (
- Run in Cuckoo Sandbox to observe:
- Reverse Engineering:
- Use Ghidra to disassemble the encryption function.
- Find the XOR key used for encryption.
- Decryption:
- Write a Python script to reverse the XOR operation and recover files.
Malware Detection and Mitigation
Detection Methods
| Method | Description | Tools/Techniques |
|---|---|---|
| Signature-Based | Compares malware against a database of known signatures. | ClamAV, Windows Defender |
| Heuristic Analysis | Detects suspicious behavior (e.g., rapid file encryption). | Behavior-based AVs (e.g., CrowdStrike) |
| Anomaly Detection | Uses machine learning to detect deviations from normal behavior. | Darktrace, Splunk |
| Sandboxing | Runs suspicious files in an isolated environment to observe actions. | Cuckoo Sandbox, Any.run |
Mitigation Strategies
| Strategy | How It Works | Example |
|---|---|---|
| Isolation | Quarantine infected systems to prevent spread. | Air-gapped networks for critical systems. |
| Patch Management | Apply security updates to close vulnerabilities. | Microsoft Patch Tuesday for EternalBlue. |
| Endpoint Protection | Use EDR (Endpoint Detection and Response) to monitor and block threats. | SentinelOne, CrowdStrike |
| User Training | Educate users on phishing and social engineering attacks. | Simulated phishing tests for employees. |
| Incident Response | Have a plan for containment, eradication, and recovery. | NTC’s cyber incident response team. |
Exam Tip
What to Expect in the Exam
Theory Questions (30-40%):
- Define malware, static vs. dynamic analysis, and reverse engineering.
- Explain how ransomware encrypts files (e.g., AES, RSA).
- Compare Trojan vs. Worm propagation methods.
Scenario-Based Questions (40-50%):
- Case Study: Given a malware sample (e.g., a packed executable), describe how you would analyze it.
- Example: "A bank’s ATM system is infected with a malware that logs keystrokes. How would you analyze it?"
- Expected Answer:
- Use static analysis (PEiD, strings) to check for packers.
- Run in Cuckoo Sandbox to capture keystroke logging.
- Reverse-engineer the keylogger DLL using Ghidra.
- Mitigation: "How would you protect a university network from Emotet?"
- Expected Answer:
- Deploy email filtering to block phishing.
- Use EDR tools to detect suspicious processes.
- Train staff on not opening unknown attachments.
- Expected Answer:
- Case Study: Given a malware sample (e.g., a packed executable), describe how you would analyze it.
Tool-Based Questions (20-30%):
- "Show how you would use Wireshark to detect C2 traffic."
- Expected Answer:
- Filter for unusual DNS requests (
dns.query). - Look for HTTP POST to suspicious IPs.
- Filter for unusual DNS requests (
- Expected Answer:
- "Explain how YARA rules work with an example."
- Expected Answer: Provide a YARA rule for LockBit (as shown earlier).
- "Show how you would use Wireshark to detect C2 traffic."
Key Formulas/Concepts to Remember
- Polymorphic Malware: Changes its signature on each infection.
- Metamorphic Malware: Rewrites its entire code while keeping functionality.
- C2 Communication: Malware phones home to a command-and-control server (often via DNS tunneling or HTTP).
- Encryption Algorithms: Ransomware often uses AES (symmetric) + RSA (asymmetric).
Common Pitfalls
- Assuming all malware is a virus: Some malware (e.g., spyware) doesn’t replicate.
- Ignoring static analysis: Always check strings and headers before dynamic analysis.
- Running malware on a live system: Always use a sandbox or VM.
Based on the PU BE Computer (PU) syllabus for Network and Cyber Security (CMP426), unit 9.
Discussion
Loading…