12 - Dissecting FlawedAmmyy - Part 1

Preview unavailable

You must log in or sign up to view this lesson.

LoginSign up

Malware Analyst Professional - Level 1

Buy nowLearn more

Course Resources

  • Malware Analyst Professional - Level 1 Syllabus.pdf
  • For serious people only - MAoS - Malware Analysis on Steroids

Module 1: Foundations & Lab Setup

  • Malware Analysis Lab OVA Deployment
  • 1 - Introduction to Malware Analysis
  • 2 - Lab Setup - Intro
  • 3 - Lab Setup - Deploying Flare-VM
  • 4 - Lab Setup - Connecting to INetSim

Module 2: From Source to Assembly: Building & Peeking Inside C Programs

  • 1 - Installing Visual Studio
  • 2 - The four stages of Development
  • 3 - Basic C Code Example - Part 1
  • 4 - Basic C Code Example - Part 2
  • example1.c
  • example2.c
  • 5 - Basic Reverse Engineering - Part 1
  • 6 - Basic Reverse Engineering - Part 2

Module 3: Peering into Portable Executables

  • 1 - PE Structure Overview - Part 1
  • 2 - PE Structure Overview - Part 2
  • 3 - PE-exe vs. PE-dll

Module 4: Static Triage, Unpacking & Real-World Walk-Through

  • 1 - Purpose and Goals of Malware Analysis
  • 2 - Understanding Signature Names and VirusTotal Overview
  • 3 - IoC vs. IoA
  • 4 - Identifying File Types
  • 5 - Calculating Hashes
  • 6 - Strings Extraction
  • 7 - Packing Analysis - Part 1
  • 8 - Packing Analysis - Part 2
  • 9 - Packing Analysis - Part 3
  • 10 - Identifying Malicious Functionality
  • 11 - Approaching and Reading Documentations
  • 12 - Dissecting FlawedAmmyy - Part 1
  • 13 - Dissecting FlawedAmmyy - Part 2
  • 14 - Saving your RE progress to an IDB File

Module 5: Live Behaviour & Dynamic Reverse Engineering

  • 1 - Introduction to Dynamic Analysis
  • 2 - Working with Process Explorer
  • 3 - Extracting IoCs using Process Hacker
  • 4 - Working with Procmon
  • 5 - Monitoring WinAPI Functions using API Logger
  • 6 - Inspecting Process Command Line Parameters using CMD Watcher
  • 7 - Debugging DLL Files with IDA Disassembler
  • 8 - FlawedAmmyy RAT - Attack Flow PCAP Analysis Overview
  • 9 - FlawedAmmyy RAT Dynamic Analysis
  • 10 - FlawedAmmyy RAT Dynamic Reverse Engineering - Part 1
  • 11 - FlawedAmmyy RAT Dynamic Reverse Engineering - Part 2
  • 12 - Detecting FlawedAmmyy RAT with YARA

Module 6: Dissecting Malicious Documents: PDFs & Office Macros

  • 1 - Introduction to Malicious Documents
  • 2 - Introduction to Analyzing Malicious PDF Files
  • 3 - Analyzing the CVE-2008-2992 PDF Exploit
  • 4 - Analyzing VBA Macros - Introduction
  • 5 - Analyzing VBA Macros - Shellcode Injection

Malware Lab Samples

  • 404 Not Found - Isn't that a Mystery?!
  • space1 - FlawedAmmyy.zip
  • Malicious Documents Lab Samples.zip

YARA Rules

  • sodinokibi.yara
  • PE.yara
  • WannaCry.yara
  • UPX.yara
  • Cryak.yara