This workshop provides builds on the fundamentals from re101 for reversing engineering (RE) Windows malware using a hands-on experience with RE tools and techniques. The purpose of this workshop is to get you familiar with Anti Reverse Engineering, Encryption, VM Evasion and Packing techniques.The course will conclude by participants performing hands-on malware analysis that consists of Triage, Static, and Dynamic analysis.
Overview
Syllabus
Introduction
Environment Setup
Information Gathering Exercise
Information Gathering Results
Creating Travel Directions
Lab 1 Static Analysis
Lab 1 Results
Lab 2 Identifying Encryption
Lab 2 Identifying the Decryption Algorithm
Lab 3 Writing a Decryptor
Lab 4 Convert the Shellcode Into an Exe
Lab 5 Evasion Techniques
Lab 6 Debugging Around Evasion
Lab 7 Evasion Techniques
Lab 8 Identifying Packing
Lab 8 The Unpacking Script
Extra Exercises
Closing Remarks