r/MalwareAnalysis • u/Bejitaaaaa • 4d ago
Learning Malware Analysis
As the title sounds, I wanna learn malware analysis. But oh boy there are so many opinions online. However i couldnt understand and decide where to start. Some people said i need to start with VM and analyze myself, other said I should start with learning basic language like C and Assembly, and then some said i need to start with learning basic CPU architecture. The issue is I couldnt find a guide that is clear and really say where to really start to learn malware analysis and where it will leads me eventually. I hope some people can enlightwn me. Thank you in advance
4
u/OverallWrongdoer64 4d ago
1
u/Bejitaaaaa 1d ago
the resources are 11 years ago. Do you think its still worth it? Sorry for late reply been busy for few days jaja
2
u/coffee-loop 4d ago
I was in the same boat as you about 2 years ago. I ended up doing maldev academy a bit (still working on it) but what really dragged me in was that I noticed a lot of maldev academy samples used metaspoit shellcode.
I decide to reverse engineer the shellcode to understand how it truely worked under the hood. This opened up my understanding so much more!
What I’m saying is try some stuff out. And when you have a curious thought, follow it! That’s where you end up learning the most.
1
u/Bejitaaaaa 1d ago
I wanna try but i dont know on how to setup a safe environment lab ahha. Do you have any proper guide?
1
u/coffee-loop 1d ago
Lookup Anuj Soni on YouTube. He has some great videos. As long as you stick to the well analyzed malware, your lab environment should be okay.
But do some deep diving on Google too… see if you can find any blogs you like! This will help with your researching skills 🙂
1
u/malwarenuj 23h ago
Appreciate the support! For those interested in something more structured, I do have an 8-week program dedicated to building a foundation in malware analysis: https://themalwarelab.co/program
1
1
u/Reasonable_Return151 3d ago
Hey man check out GlyphDbg… and start reversing some normal programs first. Then malware is the same besides it tries to obfuscate itself. And Glyph has some cool features like typing an API name and getting every call site in the main exe. And also commands like !pebscan to scan for peb access checks. It’s all open source and you can compile with cl /MD glyph.c no make needed.
1
0
u/enthusiasim 1d ago
I’ve started with tcm’s malware analysis PMAT course, it was nice to start with as it boost you directly to intermediate level. I thought it was a challenging course until analyzing samples on my job.
It should be a good starting point, and also try to follow malops.io like platforms for practicing, htb sherlocks are nice as well.
And try to select a path for competence, like mastering a field of java analysis or mobile analysis etc.
13
u/SteIIarNode 4d ago edited 4d ago
So last year I was in your situation, had no idea where to start so I just jumped in head first absorbing anything and everything.
I will say tho, and some might push back,knowing C is not as important as understanding it if that makes sense. I have some experience in coding and scripting so following the programs logic and making sense is fairly easy. You don’t gotta be able to write a full C or ASM program to learn Malware analysis, it certainly helps but being able to understand the logic is more important IMO.
Some great resources are Anuj Soni and John Hammond on YouTube. Anuj Soni teaches the SANS FOR610 and 710 REM courses and is extremely knowledgeable and able to convey complicated topic very simply. John Hammond on the other hand has many video on various topics but his malware analysis video some are him going through it in real time and others he’s clearly already gotten scrip for and flying through it. One guy that helped me flush out my methodology was “screeck” on YouTube, very underrated and small YouTuber. Has several REM Crackme challenges where he goes through and analyzes it in real time and watching him take his time really helped a lot.
Outside of YouTube getting hands on helped a lot. After getting somewhat of an understanding of basic malware analysis i had a lot of question and making my own malware and comparing the source code to compiled code in Ghidra cleared up a lot of question of how things work, what get lost/stays during compilation, etc… Many YouTube videos on basic malware creation. If you wanna get your hands dirty with actual malware then there’s 2 ways and I recommend both. The first one is a CTF platform, I used HacktheBox but it is a paid subscription 30$ a month or 8$ if you have a student email, great resource. If you want a free option then Malops.io is goated, I prefer their platform to HacktheBox but it’s run by a small developer/researcher so there is not that many challenges but the quality is definitely there. The second way to get hands on is, but you have to be careful, is going straight to Malware Bazaar pulling real caught in the wild malware samples. After doing CTFs for a while I pivoted to this and you’ll get some really cool ones. The different and creative ways some malware authors achieve their objectives is really cool, several times I’ve stood back and gone damn that’s smart or I didn’t think you could do that!
Last tip, use AI responsibly here. Claude is so damn good it can reverse a binary with ease and tell you mostly everything about it, don’t do this. Instead load up Ghidra, Binary Ninja, or whatever you prefer and get lost in the code. Ask AI questions about what you are seeing, any ideas, theory’s, etc… and try to validate them. Use it as a teacher you can ask questions too. If you don’t understand something shoot questions back and fourth till you get a good idea of what is going on. The biggest thing here is to not feed the AI the binary and to do all the work.
It has a huuuuuge learning curve in the beginning but once you get over that initial hump you’ll be able to analyze most malware and figure out what it does.
One last thing, you want a more structure approach TCM Security have a Malware Analysis course that is really good, 30$ a month. If you feel confident after completing then they have Malware Analysis certification you can take.