Skip to main content

reverser-malware-triage

Fast malware triage workflow — static (PE/Mach-O/ELF format, strings, imports, signatures, entropy/packed indicators), dynamic (sandbox with INetSim, Wireshark, Process Monitor, Procmon, time-shift), unpack (Scylla/PE-sieve), then full RE with Ghidra/IDA. Designed for ≤15 min initial verdict.

설치로 이동

소스 정보

저장소
BitterSecurity/Decepticon
최근 소스 활동
2026년 5월 26일 09:25
감지된 SKILL.md 언어
영어
스타
5,565
포크
1,053

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
reverser-malware-triage
description
Fast malware triage workflow — static (PE/Mach-O/ELF format, strings, imports, signatures, entropy/packed indicators), dynamic (sandbox with INetSim, Wireshark, Process Monitor, Procmon, time-shift), unpack (Scylla/PE-sieve), then full RE with Ghidra/IDA. Designed for ≤15 min initial verdict.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"malware triage sample first look static dynamic sandbox cuckoo capemon inetsim wireshark procmon unpack packed entropy yara","subdomain":"reverser","tags":"malware, triage, sandbox, ghidra","mitre_attack":"T1059, T1518"}
# Malware Triage — 15 minute first verdict You have a suspicious binary. Goal: in 15 minutes, decide CLEAN / SUSPICIOUS / MALICIOUS / NEEDS-DEEPER. ## Phase 1: Static (5 min) ```bash # 1. File format file sample.bin exiftool sample.bin # author / compile timestamp / version # 2. Hash + reputation sha256sum sample.bin # Submit to: VirusTotal, MalwareBazaar, IntelX, Joe Sandbox, ANY.RUN # Often the verdict already exists — saves you 14 minutes. # 3. Strings — fast triage signal strings -n 8 sample.bin | sort -u | head -100 strings -e l -n 8 sample.bin | sort -u | head -50 # wide (UTF-16) strings on Windows # Suspicious strings to grep for: strings sample.bin | grep -iE 'http|https|wmic|powershell|cmd.exe|temp|appdata|amsi|defender|reflectiveloader' # 4. Format-specific: PE peresearcher sample.exe # OR python pefile python3 -c ' import pefile p = pefile.PE("sample.exe") print("Compile time:", p.FILE_HEADER.TimeDateStamp) print("Sections:", [(s.Name.decode().rstrip("\x00"), s.SizeOfRawData, s.get_entropy()) for s in p.sections]) print("Imports:", [(e.dll.decode(), [i.name.decode() if i.name else hex(i.ordinal) for i in e.imports]) for e in p.DIRECTORY_ENTRY_IMPORT]) ' # 5. Entropy → packed? python3 -c ' import math data = open("sample.bin","rb").read() counts = [data.count(bytes([b])) for b in range(256)] total = len(data) ent = -sum((c/total)*math.log2(c/total) for c in counts if c) print(f"Entropy: {ent:.3f} / 8 — {'packed' if ent > 7.5 else 'normal'}") ' # 6. YARA against canonical rulesets yara -r /opt/yara-rules/ sample.bin yara -r /opt/Neo23x0-signature-base/ sample.bin ``` ## Phase 2: Dynamic (5 min — in an isolated VM) ```bash # Pre-flight (do this once, save snapshot) # - Disconnected network OR use INetSim/FakeNet-NG to fake services # - Procmon recording (Process / File / Network / Registry filters) # - Wireshark capturing on the snapshot's network adapter # - Fakedns / inetsim listening for DNS / HTTP / SMTP / FTP # Detonate cp sample.bin C:\tmp\sample.exe # Right-click → Run as admin OR sample.exe in cmd # Observe for 60-180 seconds, then take snapshot # Then revert VM for next run ``` ### Things to look for | Signal | Verdict | |---|---| | Writes to `\AppData\Local\Temp` then executes | Likely dropper | | Creates Run/RunOnce registry key | Persistence | | Schedules a task | Persistence | | Modifies firewall via netsh | Defense evasion | | Spawns powershell + LongStringEncoded | Stage 2 | | Network: HTTPS to a no-SNI IP | C2 callback | | DNS to a DGA-looking domain | C2 callback | | Reads process memory of lsass.exe / winlogon.exe | Credential theft | | Writes to userinit / shells / image-file-exec-options | Persistence | | Touches `\Microsoft\Cryptography\Defaults\Provider` | Cert injection | ## Phase 3: Unpack (if entropy was high, optional 5 min) ```bash # In dynamic VM, after detonation, dump memory: # Scylla (UI) → attach to process, dump PE image # OR PE-sieve (command-line): pe-sieve.exe /pid 1234 /dir dumped # OR DnSpy + DotNetReactorUnpacker for .NET # OR de4dot for obfuscated .NET # Then static-re the unpacked binary (Phase 1 strings/imports against the dump) ``` ## Phase 4: Verdict + handoff | Verdict | Indicators | Next step | |---|---|---| | **CLEAN** | Known-good hash, signed, expected strings/imports, no suspicious behavior | Mark + move on | | **SUSPICIOUS** | Unsigned, low rep, mildly unusual imports/strings, no clear malicious behavior | Sandbox 30 min longer, YARA against custom rules | | **MALICIOUS** | C2 callback, drops files, persistence, credential theft, packed + evades VMs | IOC extraction, then deep RE (load `reverser/ghidra/SKILL.md`) | | **NEEDS-DEEPER** | High entropy, anti-analysis, custom-packed, no obvious signal | Unpack first (Phase 3), then re-triage | ## IOC extraction template If MALICIOUS: - Hashes (md5, sha1, sha256) - C2 domains / IPs (from PCAP) - Mutex names (Procmon: CreateMutex events) - File paths created - Registry keys modified - YARA signature (generate from unique strings/code) ## Tooling cheatsheet | Stage | Tool | Use | |---|---|---| | Static (PE) | pefile, capa, exiftool, Detect It Easy (DIE) | Format + capability scan | | Static (ELF) | readelf, objdump, radare2 | Format + symbols | | Static (Mach-O) | jtool2, otool, MachOView | Format + symbols | | Dynamic | Cuckoo, CAPE, ANY.RUN, Joe Sandbox, Hatching Triage | Automated sandbox | | Network | Wireshark, mitmproxy, FakeNet-NG, INetSim | Traffic capture + fake services | | Memory | Volatility 3, PE-sieve, Scylla | Memory forensics + unpacking | | Disassembly | Ghidra, IDA, Binary Ninja | Full RE — see `reverser/ghidra/SKILL.md` | | YARA | yara, capa rules | Signature matching | ## References - "Practical Malware Analysis" — Sikorski & Honig (still the canonical book) - MITRE ATT&CK — for behavior → technique mapping - Lenny Zeltser's "REMnux" — pre-built malware analysis distro - DEFCON "Malware Forensics" track recordings
GitHub에서 보기