Reverse Engineering Modern Malware with Ghidra: A Hands-On Guide

Reverse Engineering Modern Malware with Ghidra

Setting Up Ghidra

Download from ghidra-sre.org and ensure you have JDK 17+ installed.

Sample Analysis: Lumma Stealer

We’ll analyze a recent Lumma Stealer sample (SHA256: a1b2c3d4...).

Initial Triage

$ file sample.exe
sample.exe: PE32+ executable (GUI) x86-64, for MS Windows

$ strings sample.exe | head -20
...
kernel32.dll
advapi32.dll
crypt32.dll
...

Anti-Analysis Techniques

The sample employs several anti-analysis techniques:

  1. VM Detection – Checks for VMware, VirtualBox artifacts
  2. Debugger Detection – IsDebuggerPresent, CheckRemoteDebuggerPresent
  3. Timing Checks – RDTSC-based timing analysis
// Decompiled anti-VM check
BOOL CheckVM() {
    HKEY hKey;
    RegOpenKeyExA(HKEY_LOCAL_MACHINE,
        "SYSTEM\\CurrentControlSet\\Services\\Disk\\Enum",
        0, KEY_READ, &hKey);
    // Checks for "VMware", "VBOX", "QEMU" in device names
}

Extracting IOCs

Using Ghidra’s script manager, we can automate IOC extraction:

# Ghidra Python script
from ghidra.app.decompiler import DecompInterface
from ghidra.util.task import ConsoleTaskMonitor

def extract_strings():
    # Extract all strings and filter for URLs, IPs, domains
    pass

Conclusion

Ghidra has become an indispensable tool for malware analysis. Its decompiler, scripting capabilities, and active community make it a viable alternative to commercial tools.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *