- name
- malware-analysis-multios
- description
- Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.
# Multiplatform Malware Analysis (Multi-OS Malware Analysis)
This skill establishes the methodological flows for reverse engineering, behavioral analysis, deobfuscation, and cataloging of malicious artifacts across **Windows (PE)**, **Linux (ELF)**, **Android (APK/DEX)**, and **macOS (Mach-O)** ecosystems.
---
## 🔬 1. Four-Phase Analysis Methodology
```
┌─────────────────────────────────────────────────────────────┐
│ 1. Basic Static Analysis (Hashes, Strings, Headers, PE/ELF) │
└──────────────────────────────┬──────────────────────────────┘
│
┌──────────────────────────────▼──────────────────────────────┐
│ 2. Basic Dynamic Analysis (Sandbox, Network, Registry, Proc)│
└──────────────────────────────┬──────────────────────────────┘
│
┌──────────────────────────────▼──────────────────────────────┐
│ 3. Advanced Static Analysis (Ghidra, IDA, JADX, Decompil.) │
└──────────────────────────────┬──────────────────────────────┘
│
┌──────────────────────────────▼──────────────────────────────┐
│ 4. Advanced Dynamic Analysis (Debugging with x64dbg/GDB) │
└─────────────────────────────────────────────────────────────┘
```
---
## 🪟 2. Windows PE Internals and Unpacking
### 2.1 PE Anatomy
- **DOS stub** → `0x3c` PE offset → **COFF header** → **Optional Header** (PE32 `0x10b` / PE32+ `0x20b`) → **section table** (40-byte entries) → **data directories** (Export, Import, Resource, Exception, Certificate, Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import, CLR).
- **Key structures**: IAT/EAT, TLS callbacks (run before the entry point), delay-load imports, the resource section (common hiding place), and DLL characteristics such as `GUARD_CF` (0x4000) and `NX_COMPAT` (0x0100).
- **Packer detection signals**: high-entropy `.text`, few or reconstructed imports, PEiD-style signatures, and dynamic API resolution.
### 2.2 Unpacking
- **Passive unpacking**: capture the payload when the packer writes it to memory (process hollowing, doppelgänging, memory extraction from the sandbox).
- **Active unpacking**: break on writes to freshly allocated or newly executable memory to catch the Original Entry Point (OEP), then dump and rebuild the import table.
- **Common families**: UPX (trivial), VMProtect and Themida (virtualization and anti-debug), and custom crypter stubs.
- **Anti-analysis**: anti-VM, anti-debug, anti-sandbox timing checks, and control-flow flattening. Document every anti-analysis artifact as an ATT&CK technique (T1497, T1027).
### 2.3 Detection Engineering
- **YARA**: file and memory signatures with `pe`/`elf`/`dotnet`/`lnk` modules, string modifiers (`ascii`, `wide`, `nocase`) and hash/math conditions.
- **Sigma**: vendor-neutral detection rules converted to SIEM queries; author in Sigma so the detection is portable.
- **Behavioral signatures**: correlate process injection (`VirtualAllocEx` → `WriteProcessMemory` → `CreateRemoteThread`), persistence writes and C2 beaconing rather than relying on a single string.
---
## 🧬 3. Malware Taxonomy and C2 Tradecraft
| Family | Primary behavior | Notable ATT&CK mapping |
| :--- | :--- | :--- |
| **Ransomware** | Encrypts data and demands payment | T1486 (Data Encrypted for Impact) |
| **RAT / Backdoor** | Remote control, keylogging | T1219, T1056 |
| **Infostealer** | Harvests credentials, cookies, wallets | T1555, T1552 |
| **Loader / Stager** | Downloads and executes the next stage | T1105, T1620 |
| **Rootkit / Bootkit** | Hides presence, persists below the OS | T1014, T1542 |
| **Fileless** | Lives in memory or in legitimate interpreters | T1059, T1620 |
| **Worm / Botnet** | Self-propagates, joins a C2 network | T1210, T1583 |
- **C2 protocols**: HTTP(S) beaconing, DNS tunneling, named pipes, and covert channels; extract the **configuration** (endpoints, keys, intervals) whenever possible.
- **Naming**: map to the vendor/CARO naming scheme and keep an alias table; names are labels, not identity.
---
## 📱 4. Android Malware Analysis (APK / DEX / Native SO)
- **APK Structure**: Extraction of `AndroidManifest.xml`, `classes.dex`, resources, and C/C++ shared libraries (`lib/*.so`).
- **Decompilation**: Use of **JADX** to recover Java/Kotlin code and **Ghidra** for analysis of native ARM binaries (JNI).
- **Common Vulnerabilities and Vectors**:
- *Accessibility Services Abuse*: Keylogging and overlay attacks in banking apps.
- *Dynamic Code Loading (DCL)*: Downloading encrypted payloads at runtime through `DexClassLoader`.
- *Native Obfuscation (OLLVM)*: Control flow flattening and encrypted strings in native C code.
---
## 🍏 5. macOS Malware Analysis (Mach-O)
- **Mach-O Structure**: Headers, load commands (`LC_LOAD_DYLIB`, `LC_CODE_SIGNATURE`, `LC_MAIN`), sections (`__TEXT`, `__DATA`).
- **macOS Persistence Mechanisms**:
- *LaunchDaemons* (`/Library/LaunchDaemons`) and *LaunchAgents* (`~/Library/LaunchAgents`).
- *Login Items* and *Cron Jobs*.
- *Dylib Hijacking* (exploitation of `@rpath` and missing libraries).
- **macOS Security Bypasses**: Techniques to circumvent Gatekeeper, Notarization, and TCC (Transparency, Consent, and Control).
---
## 📜 6. Creating YARA Detection Rules
```yara
rule Suspicious_MultiOS_Payload {
meta:
author = "Antigravity Security Specialist"
description = "Detects code injection routines and obfuscated strings"
date = "2026-08-28"
strings:
$api1 = "NtAllocateVirtualMemory" ascii wide
$api2 = "WriteProcessMemory" ascii wide
$magic_pe = { 4D 5A }
$magic_elf = { 7F 45 4C 46 }
$magic_macho = { FE ED FA CE }
condition:
($magic_pe at 0 or $magic_elf at 0 or $magic_macho at 0) and
all of ($api*)
}
```
GitHubで見る