Skip to main content

malware-analysis-multios

Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.

Informações da origem

Repositório
dandgabr/Coacus
Última atividade na origem
28 de setembro de 2026 às 14:03
Idioma detectado do SKILL.md
inglês
Estrelas
4
Forks
3

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Explorador de arquivos
5 arquivos

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
malware-analysis-multios
description
Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.
# Multiplatform Malware Analysis (Multi-OS Malware Analysis) This skill establishes the methodological flows for reverse engineering, behavioral analysis, deobfuscation, and cataloging of malicious artifacts across **Windows (PE)**, **Linux (ELF)**, **Android (APK/DEX)**, and **macOS (Mach-O)** ecosystems. --- ## 🔬 1. Four-Phase Analysis Methodology ``` ┌─────────────────────────────────────────────────────────────┐ │ 1. Basic Static Analysis (Hashes, Strings, Headers, PE/ELF) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 2. Basic Dynamic Analysis (Sandbox, Network, Registry, Proc)│ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 3. Advanced Static Analysis (Ghidra, IDA, JADX, Decompil.) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 4. Advanced Dynamic Analysis (Debugging with x64dbg/GDB) │ └─────────────────────────────────────────────────────────────┘ ``` --- ## 🪟 2. Windows PE Internals and Unpacking ### 2.1 PE Anatomy - **DOS stub** → `0x3c` PE offset → **COFF header** → **Optional Header** (PE32 `0x10b` / PE32+ `0x20b`) → **section table** (40-byte entries) → **data directories** (Export, Import, Resource, Exception, Certificate, Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import, CLR). - **Key structures**: IAT/EAT, TLS callbacks (run before the entry point), delay-load imports, the resource section (common hiding place), and DLL characteristics such as `GUARD_CF` (0x4000) and `NX_COMPAT` (0x0100). - **Packer detection signals**: high-entropy `.text`, few or reconstructed imports, PEiD-style signatures, and dynamic API resolution. ### 2.2 Unpacking - **Passive unpacking**: capture the payload when the packer writes it to memory (process hollowing, doppelgänging, memory extraction from the sandbox). - **Active unpacking**: break on writes to freshly allocated or newly executable memory to catch the Original Entry Point (OEP), then dump and rebuild the import table. - **Common families**: UPX (trivial), VMProtect and Themida (virtualization and anti-debug), and custom crypter stubs. - **Anti-analysis**: anti-VM, anti-debug, anti-sandbox timing checks, and control-flow flattening. Document every anti-analysis artifact as an ATT&CK technique (T1497, T1027). ### 2.3 Detection Engineering - **YARA**: file and memory signatures with `pe`/`elf`/`dotnet`/`lnk` modules, string modifiers (`ascii`, `wide`, `nocase`) and hash/math conditions. - **Sigma**: vendor-neutral detection rules converted to SIEM queries; author in Sigma so the detection is portable. - **Behavioral signatures**: correlate process injection (`VirtualAllocEx` → `WriteProcessMemory` → `CreateRemoteThread`), persistence writes and C2 beaconing rather than relying on a single string. --- ## 🧬 3. Malware Taxonomy and C2 Tradecraft | Family | Primary behavior | Notable ATT&CK mapping | | :--- | :--- | :--- | | **Ransomware** | Encrypts data and demands payment | T1486 (Data Encrypted for Impact) | | **RAT / Backdoor** | Remote control, keylogging | T1219, T1056 | | **Infostealer** | Harvests credentials, cookies, wallets | T1555, T1552 | | **Loader / Stager** | Downloads and executes the next stage | T1105, T1620 | | **Rootkit / Bootkit** | Hides presence, persists below the OS | T1014, T1542 | | **Fileless** | Lives in memory or in legitimate interpreters | T1059, T1620 | | **Worm / Botnet** | Self-propagates, joins a C2 network | T1210, T1583 | - **C2 protocols**: HTTP(S) beaconing, DNS tunneling, named pipes, and covert channels; extract the **configuration** (endpoints, keys, intervals) whenever possible. - **Naming**: map to the vendor/CARO naming scheme and keep an alias table; names are labels, not identity. --- ## 📱 4. Android Malware Analysis (APK / DEX / Native SO) - **APK Structure**: Extraction of `AndroidManifest.xml`, `classes.dex`, resources, and C/C++ shared libraries (`lib/*.so`). - **Decompilation**: Use of **JADX** to recover Java/Kotlin code and **Ghidra** for analysis of native ARM binaries (JNI). - **Common Vulnerabilities and Vectors**: - *Accessibility Services Abuse*: Keylogging and overlay attacks in banking apps. - *Dynamic Code Loading (DCL)*: Downloading encrypted payloads at runtime through `DexClassLoader`. - *Native Obfuscation (OLLVM)*: Control flow flattening and encrypted strings in native C code. --- ## 🍏 5. macOS Malware Analysis (Mach-O) - **Mach-O Structure**: Headers, load commands (`LC_LOAD_DYLIB`, `LC_CODE_SIGNATURE`, `LC_MAIN`), sections (`__TEXT`, `__DATA`). - **macOS Persistence Mechanisms**: - *LaunchDaemons* (`/Library/LaunchDaemons`) and *LaunchAgents* (`~/Library/LaunchAgents`). - *Login Items* and *Cron Jobs*. - *Dylib Hijacking* (exploitation of `@rpath` and missing libraries). - **macOS Security Bypasses**: Techniques to circumvent Gatekeeper, Notarization, and TCC (Transparency, Consent, and Control). --- ## 📜 6. Creating YARA Detection Rules ```yara rule Suspicious_MultiOS_Payload { meta: author = "Antigravity Security Specialist" description = "Detects code injection routines and obfuscated strings" date = "2026-08-28" strings: $api1 = "NtAllocateVirtualMemory" ascii wide $api2 = "WriteProcessMemory" ascii wide $magic_pe = { 4D 5A } $magic_elf = { 7F 45 4C 46 } $magic_macho = { FE ED FA CE } condition: ($magic_pe at 0 or $magic_elf at 0 or $magic_macho at 0) and all of ($api*) } ```
Ver no GitHub