Reverse Engineering Modern Malware with Ghidra
Setting Up Ghidra
Download from ghidra-sre.org and ensure you have JDK 17+ installed.
Sample Analysis: Lumma Stealer
We’ll analyze a recent Lumma Stealer sample (SHA256: a1b2c3d4...).
Initial Triage
$ file sample.exe
sample.exe: PE32+ executable (GUI) x86-64, for MS Windows
$ strings sample.exe | head -20
...
kernel32.dll
advapi32.dll
crypt32.dll
...
Anti-Analysis Techniques
The sample employs several anti-analysis techniques:
- VM Detection – Checks for VMware, VirtualBox artifacts
- Debugger Detection –
IsDebuggerPresent,CheckRemoteDebuggerPresent - Timing Checks – RDTSC-based timing analysis
// Decompiled anti-VM check
BOOL CheckVM() {
HKEY hKey;
RegOpenKeyExA(HKEY_LOCAL_MACHINE,
"SYSTEM\\CurrentControlSet\\Services\\Disk\\Enum",
0, KEY_READ, &hKey);
// Checks for "VMware", "VBOX", "QEMU" in device names
}
Extracting IOCs
Using Ghidra’s script manager, we can automate IOC extraction:
# Ghidra Python script
from ghidra.app.decompiler import DecompInterface
from ghidra.util.task import ConsoleTaskMonitor
def extract_strings():
# Extract all strings and filter for URLs, IPs, domains
pass
Conclusion
Ghidra has become an indispensable tool for malware analysis. Its decompiler, scripting capabilities, and active community make it a viable alternative to commercial tools.
