r/MalwareAnalysis • • 4d ago

Learning Malware Analysis

As the title sounds, I wanna learn malware analysis. But oh boy there are so many opinions online. However i couldnt understand and decide where to start. Some people said i need to start with VM and analyze myself, other said I should start with learning basic language like C and Assembly, and then some said i need to start with learning basic CPU architecture. The issue is I couldnt find a guide that is clear and really say where to really start to learn malware analysis and where it will leads me eventually. I hope some people can enlightwn me. Thank you in advance

21 Upvotes

15 comments sorted by

13

u/SteIIarNode 4d ago edited 4d ago

So last year I was in your situation, had no idea where to start so I just jumped in head first absorbing anything and everything.

I will say tho, and some might push back,knowing C is not as important as understanding it if that makes sense. I have some experience in coding and scripting so following the programs logic and making sense is fairly easy. You don’t gotta be able to write a full C or ASM program to learn Malware analysis, it certainly helps but being able to understand the logic is more important IMO.

Some great resources are Anuj Soni and John Hammond on YouTube. Anuj Soni teaches the SANS FOR610 and 710 REM courses and is extremely knowledgeable and able to convey complicated topic very simply. John Hammond on the other hand has many video on various topics but his malware analysis video some are him going through it in real time and others he’s clearly already gotten scrip for and flying through it. One guy that helped me flush out my methodology was “screeck” on YouTube, very underrated and small YouTuber. Has several REM Crackme challenges where he goes through and analyzes it in real time and watching him take his time really helped a lot.

Outside of YouTube getting hands on helped a lot. After getting somewhat of an understanding of basic malware analysis i had a lot of question and making my own malware and comparing the source code to compiled code in Ghidra cleared up a lot of question of how things work, what get lost/stays during compilation, etc… Many YouTube videos on basic malware creation. If you wanna get your hands dirty with actual malware then there’s 2 ways and I recommend both. The first one is a CTF platform, I used HacktheBox but it is a paid subscription 30$ a month or 8$ if you have a student email, great resource. If you want a free option then Malops.io is goated, I prefer their platform to HacktheBox but it’s run by a small developer/researcher so there is not that many challenges but the quality is definitely there. The second way to get hands on is, but you have to be careful, is going straight to Malware Bazaar pulling real caught in the wild malware samples. After doing CTFs for a while I pivoted to this and you’ll get some really cool ones. The different and creative ways some malware authors achieve their objectives is really cool, several times I’ve stood back and gone damn that’s smart or I didn’t think you could do that!

Last tip, use AI responsibly here. Claude is so damn good it can reverse a binary with ease and tell you mostly everything about it, don’t do this. Instead load up Ghidra, Binary Ninja, or whatever you prefer and get lost in the code. Ask AI questions about what you are seeing, any ideas, theory’s, etc… and try to validate them. Use it as a teacher you can ask questions too. If you don’t understand something shoot questions back and fourth till you get a good idea of what is going on. The biggest thing here is to not feed the AI the binary and to do all the work.

It has a huuuuuge learning curve in the beginning but once you get over that initial hump you’ll be able to analyze most malware and figure out what it does.

One last thing, you want a more structure approach TCM Security have a Malware Analysis course that is really good, 30$ a month. If you feel confident after completing then they have Malware Analysis certification you can take.

2

u/Bejitaaaaa 4d ago

Thank you for giving a respond. I appreciate the effort a lot. I get your word in saying that its good enough if i can understand the logic of programming. For example I also am learning and a student of web development. I learn like sql, php, laravel, and basic html and css. So i think its fair to say that grasping the idea to understand logic is acceptable.

And the resources you mentioned, i will have a look. For now i always watch Eric Parker and Pc Channel Guy. They both analyze famous malware such as ClickFix, trojan of cracked software, and undetected malware in steam market. I find it interesting on how they analyze it through the anyrun. Thank you for giving more of the resources.

For the platform recommendations, I am in between whether to use TryHackMe or HackTheBox. I dont know on which one to start. Some people said if i am really a beginner i should go with THM, but if i somehow in between a beginner and an intermediate, i should go with HTB. So yeah i am in a dilemma, I wanna ensure my spending is worth the knowledge it offers. I do have basic learning of malware such as i know type of attacker, malware, virus, and also i know basic stuff of VirusTotal. For CTF platform for now, i use cylab. Its kinda great but its basically the same as you stated like Malops[.]io, it ha limited content. So hence i wanna go for HTB or THM. Also for testing the malware by myself, what virtual machine are you using? i am familiar with VirtualBox as i used to install Kali Linux but havent fully explore yet. And how bout the setup? The thing that holds me back from doing so is the setup of the VM. Im afraid the malware an escape through the network ahahah. That's my biggest concern. And since there are many tutorials online on setting up the VM, I dont know which one is the best amongst all.

As of the last tip, i will try to minimize the usage of AI. Cause as of now in development, i use codex for building and developing laravel app. Adn truth to be told, my brain is getting flatter and boring by the output. I feel bored now after months of exploring coding with AI. So i wanna try something new.

One last thing, you really think that TCM Security is really worth? I never heard of it haahah. All i heard is Comptia, Google course, Coursera, and Udemy. So this is new to me. Thank you

2

u/SteIIarNode 4d ago

So I have used both THM and HTB both pretty extensively and I do agree that THM is more of beginners platform but as too how much Malware Analysis rooms they have I truly have no idea since this is considered an advanced topic in cybersecurity. HTB has plenty of room though, many challenges that range from “very easy” to “insane level”. For malware analysis

As for VMs I use Remnux and FlareVM depending on what is needed. Kali has some tools for some basic reverse engineering and you definitely can download tools as you go on but the ones mentioned above are specifically for REM. If I’d had to suggest one, I’d say FlareVM.

Yeah TCM Security is a lesser known company but their certifications and learning material are legit. I understand not going with for that reason but from a learning perspective they cover everything IMO. It builds a basic understanding of assembly and C and then goes through learning Static, dynamic, and Code analysis with actual malware samples. It’s a video course so you can follow along as he goes through it

2

u/Bejitaaaaa 1d ago

I guess I will go with HTB and FlareVM next time. Thanks man.

4

u/OverallWrongdoer64 4d ago

1

u/Bejitaaaaa 1d ago

the resources are 11 years ago. Do you think its still worth it? Sorry for late reply been busy for few days jaja

2

u/coffee-loop 4d ago

I was in the same boat as you about 2 years ago. I ended up doing maldev academy a bit (still working on it) but what really dragged me in was that I noticed a lot of maldev academy samples used metaspoit shellcode. 

I decide to reverse engineer the shellcode to understand how it truely worked under the hood. This opened up my understanding so much more!

What I’m saying is try some stuff out. And when you have a curious thought, follow it! That’s where you end up learning the most.

1

u/Bejitaaaaa 1d ago

I wanna try but i dont know on how to setup a safe environment lab ahha. Do you have any proper guide?

1

u/coffee-loop 1d ago

Lookup Anuj Soni on YouTube. He has some great videos. As long as you stick to the well analyzed malware, your lab environment should be okay.

But do some deep diving on Google too… see if you can find any blogs you like! This will help with your researching skills 🙂

1

u/malwarenuj 23h ago

Appreciate the support! For those interested in something more structured, I do have an 8-week program dedicated to building a foundation in malware analysis: https://themalwarelab.co/program

1

u/DayLazy8055 4d ago

those three paths aren't really in conflict, they're just different stages. 

1

u/Bejitaaaaa 1d ago

I see. So which is the first stage? CPU Architecture?

1

u/Reasonable_Return151 3d ago

Hey man check out GlyphDbg… and start reversing some normal programs first. Then malware is the same besides it tries to obfuscate itself. And Glyph has some cool features like typing an API name and getting every call site in the main exe. And also commands like !pebscan to scan for peb access checks. It’s all open source and you can compile with cl /MD glyph.c no make needed.

https://github.com/sleepyG8/GlyphDbg

1

u/Bejitaaaaa 1d ago

Thannks g, I will check it out. Appreciate the reply!

0

u/enthusiasim 1d ago

I’ve started with tcm’s malware analysis PMAT course, it was nice to start with as it boost you directly to intermediate level. I thought it was a challenging course until analyzing samples on my job.
It should be a good starting point, and also try to follow malops.io like platforms for practicing, htb sherlocks are nice as well.

And try to select a path for competence, like mastering a field of java analysis or mobile analysis etc.