Skip to main content

malware-analysis-multios

Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.

ソース情報

リポジトリ
dandgabr/Coacus
ソースの最終更新活動
2026年9月28日 14:03
検出された SKILL.md の言語
英語
スター
4
フォーク
3

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

ファイルエクスプローラー
5 ファイル

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
malware-analysis-multios
description
Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.
# Multiplatform Malware Analysis (Multi-OS Malware Analysis) This skill establishes the methodological flows for reverse engineering, behavioral analysis, deobfuscation, and cataloging of malicious artifacts across **Windows (PE)**, **Linux (ELF)**, **Android (APK/DEX)**, and **macOS (Mach-O)** ecosystems. --- ## 🔬 1. Four-Phase Analysis Methodology ``` ┌─────────────────────────────────────────────────────────────┐ │ 1. Basic Static Analysis (Hashes, Strings, Headers, PE/ELF) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 2. Basic Dynamic Analysis (Sandbox, Network, Registry, Proc)│ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 3. Advanced Static Analysis (Ghidra, IDA, JADX, Decompil.) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 4. Advanced Dynamic Analysis (Debugging with x64dbg/GDB) │ └─────────────────────────────────────────────────────────────┘ ``` --- ## 🪟 2. Windows PE Internals and Unpacking ### 2.1 PE Anatomy - **DOS stub** → `0x3c` PE offset → **COFF header** → **Optional Header** (PE32 `0x10b` / PE32+ `0x20b`) → **section table** (40-byte entries) → **data directories** (Export, Import, Resource, Exception, Certificate, Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import, CLR). - **Key structures**: IAT/EAT, TLS callbacks (run before the entry point), delay-load imports, the resource section (common hiding place), and DLL characteristics such as `GUARD_CF` (0x4000) and `NX_COMPAT` (0x0100). - **Packer detection signals**: high-entropy `.text`, few or reconstructed imports, PEiD-style signatures, and dynamic API resolution. ### 2.2 Unpacking - **Passive unpacking**: capture the payload when the packer writes it to memory (process hollowing, doppelgänging, memory extraction from the sandbox). - **Active unpacking**: break on writes to freshly allocated or newly executable memory to catch the Original Entry Point (OEP), then dump and rebuild the import table. - **Common families**: UPX (trivial), VMProtect and Themida (virtualization and anti-debug), and custom crypter stubs. - **Anti-analysis**: anti-VM, anti-debug, anti-sandbox timing checks, and control-flow flattening. Document every anti-analysis artifact as an ATT&CK technique (T1497, T1027). ### 2.3 Detection Engineering - **YARA**: file and memory signatures with `pe`/`elf`/`dotnet`/`lnk` modules, string modifiers (`ascii`, `wide`, `nocase`) and hash/math conditions. - **Sigma**: vendor-neutral detection rules converted to SIEM queries; author in Sigma so the detection is portable. - **Behavioral signatures**: correlate process injection (`VirtualAllocEx` → `WriteProcessMemory` → `CreateRemoteThread`), persistence writes and C2 beaconing rather than relying on a single string. --- ## 🧬 3. Malware Taxonomy and C2 Tradecraft | Family | Primary behavior | Notable ATT&CK mapping | | :--- | :--- | :--- | | **Ransomware** | Encrypts data and demands payment | T1486 (Data Encrypted for Impact) | | **RAT / Backdoor** | Remote control, keylogging | T1219, T1056 | | **Infostealer** | Harvests credentials, cookies, wallets | T1555, T1552 | | **Loader / Stager** | Downloads and executes the next stage | T1105, T1620 | | **Rootkit / Bootkit** | Hides presence, persists below the OS | T1014, T1542 | | **Fileless** | Lives in memory or in legitimate interpreters | T1059, T1620 | | **Worm / Botnet** | Self-propagates, joins a C2 network | T1210, T1583 | - **C2 protocols**: HTTP(S) beaconing, DNS tunneling, named pipes, and covert channels; extract the **configuration** (endpoints, keys, intervals) whenever possible. - **Naming**: map to the vendor/CARO naming scheme and keep an alias table; names are labels, not identity. --- ## 📱 4. Android Malware Analysis (APK / DEX / Native SO) - **APK Structure**: Extraction of `AndroidManifest.xml`, `classes.dex`, resources, and C/C++ shared libraries (`lib/*.so`). - **Decompilation**: Use of **JADX** to recover Java/Kotlin code and **Ghidra** for analysis of native ARM binaries (JNI). - **Common Vulnerabilities and Vectors**: - *Accessibility Services Abuse*: Keylogging and overlay attacks in banking apps. - *Dynamic Code Loading (DCL)*: Downloading encrypted payloads at runtime through `DexClassLoader`. - *Native Obfuscation (OLLVM)*: Control flow flattening and encrypted strings in native C code. --- ## 🍏 5. macOS Malware Analysis (Mach-O) - **Mach-O Structure**: Headers, load commands (`LC_LOAD_DYLIB`, `LC_CODE_SIGNATURE`, `LC_MAIN`), sections (`__TEXT`, `__DATA`). - **macOS Persistence Mechanisms**: - *LaunchDaemons* (`/Library/LaunchDaemons`) and *LaunchAgents* (`~/Library/LaunchAgents`). - *Login Items* and *Cron Jobs*. - *Dylib Hijacking* (exploitation of `@rpath` and missing libraries). - **macOS Security Bypasses**: Techniques to circumvent Gatekeeper, Notarization, and TCC (Transparency, Consent, and Control). --- ## 📜 6. Creating YARA Detection Rules ```yara rule Suspicious_MultiOS_Payload { meta: author = "Antigravity Security Specialist" description = "Detects code injection routines and obfuscated strings" date = "2026-08-28" strings: $api1 = "NtAllocateVirtualMemory" ascii wide $api2 = "WriteProcessMemory" ascii wide $magic_pe = { 4D 5A } $magic_elf = { 7F 45 4C 46 } $magic_macho = { FE ED FA CE } condition: ($magic_pe at 0 or $magic_elf at 0 or $magic_macho at 0) and all of ($api*) } ```
GitHubで見る