Tag: Ghidra

  • Reverse Engineering Modern Malware with Ghidra: A Hands-On Guide

    Reverse Engineering Modern Malware with Ghidra: A Hands-On Guide

    Reverse Engineering Modern Malware with Ghidra

    Setting Up Ghidra

    Download from ghidra-sre.org and ensure you have JDK 17+ installed.

    Sample Analysis: Lumma Stealer

    We’ll analyze a recent Lumma Stealer sample (SHA256: a1b2c3d4...).

    Initial Triage

    $ file sample.exe
    sample.exe: PE32+ executable (GUI) x86-64, for MS Windows
    
    $ strings sample.exe | head -20
    ...
    kernel32.dll
    advapi32.dll
    crypt32.dll
    ...
    

    Anti-Analysis Techniques

    The sample employs several anti-analysis techniques:

    1. VM Detection – Checks for VMware, VirtualBox artifacts
    2. Debugger Detection – IsDebuggerPresent, CheckRemoteDebuggerPresent
    3. Timing Checks – RDTSC-based timing analysis
    // Decompiled anti-VM check
    BOOL CheckVM() {
        HKEY hKey;
        RegOpenKeyExA(HKEY_LOCAL_MACHINE,
            "SYSTEM\\CurrentControlSet\\Services\\Disk\\Enum",
            0, KEY_READ, &hKey);
        // Checks for "VMware", "VBOX", "QEMU" in device names
    }
    

    Extracting IOCs

    Using Ghidra’s script manager, we can automate IOC extraction:

    # Ghidra Python script
    from ghidra.app.decompiler import DecompInterface
    from ghidra.util.task import ConsoleTaskMonitor
    
    def extract_strings():
        # Extract all strings and filter for URLs, IPs, domains
        pass
    

    Conclusion

    Ghidra has become an indispensable tool for malware analysis. Its decompiler, scripting capabilities, and active community make it a viable alternative to commercial tools.