Skip to main content

malware-analysis-multios

Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.

来源信息

仓库
dandgabr/Coacus
最近来源活动
2026年9月28日 14:03
检测到的 SKILL.md 语言
英语
星标
4
分支
3

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
5 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
malware-analysis-multios
description
Acts as a Specialist in Static and Dynamic Multiplatform Malware Analysis for Windows (PE), Linux (ELF), Android (APK/DEX/ARM), and macOS (Mach-O) based on The Android Malware Handbook (Qian Han) and The Art of Mac Malware (Patrick Wardle). Covers deobfuscation, decompilation, sandbox behavioral analysis, IoC extraction, YARA rules, and detection signing.
# Multiplatform Malware Analysis (Multi-OS Malware Analysis) This skill establishes the methodological flows for reverse engineering, behavioral analysis, deobfuscation, and cataloging of malicious artifacts across **Windows (PE)**, **Linux (ELF)**, **Android (APK/DEX)**, and **macOS (Mach-O)** ecosystems. --- ## 🔬 1. Four-Phase Analysis Methodology ``` ┌─────────────────────────────────────────────────────────────┐ │ 1. Basic Static Analysis (Hashes, Strings, Headers, PE/ELF) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 2. Basic Dynamic Analysis (Sandbox, Network, Registry, Proc)│ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 3. Advanced Static Analysis (Ghidra, IDA, JADX, Decompil.) │ └──────────────────────────────┬──────────────────────────────┘ │ ┌──────────────────────────────▼──────────────────────────────┐ │ 4. Advanced Dynamic Analysis (Debugging with x64dbg/GDB) │ └─────────────────────────────────────────────────────────────┘ ``` --- ## 🪟 2. Windows PE Internals and Unpacking ### 2.1 PE Anatomy - **DOS stub** → `0x3c` PE offset → **COFF header** → **Optional Header** (PE32 `0x10b` / PE32+ `0x20b`) → **section table** (40-byte entries) → **data directories** (Export, Import, Resource, Exception, Certificate, Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import, CLR). - **Key structures**: IAT/EAT, TLS callbacks (run before the entry point), delay-load imports, the resource section (common hiding place), and DLL characteristics such as `GUARD_CF` (0x4000) and `NX_COMPAT` (0x0100). - **Packer detection signals**: high-entropy `.text`, few or reconstructed imports, PEiD-style signatures, and dynamic API resolution. ### 2.2 Unpacking - **Passive unpacking**: capture the payload when the packer writes it to memory (process hollowing, doppelgänging, memory extraction from the sandbox). - **Active unpacking**: break on writes to freshly allocated or newly executable memory to catch the Original Entry Point (OEP), then dump and rebuild the import table. - **Common families**: UPX (trivial), VMProtect and Themida (virtualization and anti-debug), and custom crypter stubs. - **Anti-analysis**: anti-VM, anti-debug, anti-sandbox timing checks, and control-flow flattening. Document every anti-analysis artifact as an ATT&CK technique (T1497, T1027). ### 2.3 Detection Engineering - **YARA**: file and memory signatures with `pe`/`elf`/`dotnet`/`lnk` modules, string modifiers (`ascii`, `wide`, `nocase`) and hash/math conditions. - **Sigma**: vendor-neutral detection rules converted to SIEM queries; author in Sigma so the detection is portable. - **Behavioral signatures**: correlate process injection (`VirtualAllocEx` → `WriteProcessMemory` → `CreateRemoteThread`), persistence writes and C2 beaconing rather than relying on a single string. --- ## 🧬 3. Malware Taxonomy and C2 Tradecraft | Family | Primary behavior | Notable ATT&CK mapping | | :--- | :--- | :--- | | **Ransomware** | Encrypts data and demands payment | T1486 (Data Encrypted for Impact) | | **RAT / Backdoor** | Remote control, keylogging | T1219, T1056 | | **Infostealer** | Harvests credentials, cookies, wallets | T1555, T1552 | | **Loader / Stager** | Downloads and executes the next stage | T1105, T1620 | | **Rootkit / Bootkit** | Hides presence, persists below the OS | T1014, T1542 | | **Fileless** | Lives in memory or in legitimate interpreters | T1059, T1620 | | **Worm / Botnet** | Self-propagates, joins a C2 network | T1210, T1583 | - **C2 protocols**: HTTP(S) beaconing, DNS tunneling, named pipes, and covert channels; extract the **configuration** (endpoints, keys, intervals) whenever possible. - **Naming**: map to the vendor/CARO naming scheme and keep an alias table; names are labels, not identity. --- ## 📱 4. Android Malware Analysis (APK / DEX / Native SO) - **APK Structure**: Extraction of `AndroidManifest.xml`, `classes.dex`, resources, and C/C++ shared libraries (`lib/*.so`). - **Decompilation**: Use of **JADX** to recover Java/Kotlin code and **Ghidra** for analysis of native ARM binaries (JNI). - **Common Vulnerabilities and Vectors**: - *Accessibility Services Abuse*: Keylogging and overlay attacks in banking apps. - *Dynamic Code Loading (DCL)*: Downloading encrypted payloads at runtime through `DexClassLoader`. - *Native Obfuscation (OLLVM)*: Control flow flattening and encrypted strings in native C code. --- ## 🍏 5. macOS Malware Analysis (Mach-O) - **Mach-O Structure**: Headers, load commands (`LC_LOAD_DYLIB`, `LC_CODE_SIGNATURE`, `LC_MAIN`), sections (`__TEXT`, `__DATA`). - **macOS Persistence Mechanisms**: - *LaunchDaemons* (`/Library/LaunchDaemons`) and *LaunchAgents* (`~/Library/LaunchAgents`). - *Login Items* and *Cron Jobs*. - *Dylib Hijacking* (exploitation of `@rpath` and missing libraries). - **macOS Security Bypasses**: Techniques to circumvent Gatekeeper, Notarization, and TCC (Transparency, Consent, and Control). --- ## 📜 6. Creating YARA Detection Rules ```yara rule Suspicious_MultiOS_Payload { meta: author = "Antigravity Security Specialist" description = "Detects code injection routines and obfuscated strings" date = "2026-08-28" strings: $api1 = "NtAllocateVirtualMemory" ascii wide $api2 = "WriteProcessMemory" ascii wide $magic_pe = { 4D 5A } $magic_elf = { 7F 45 4C 46 } $magic_macho = { FE ED FA CE } condition: ($magic_pe at 0 or $magic_elf at 0 or $magic_macho at 0) and all of ($api*) } ```
在 GitHub 查看