The sophistication of malware attacks is always evolving. To circumvent common countermeasures and take advantage of vulnerabilities, they employ obfuscation, polymorphism effectively and anti-emulation strategies. Consequently, it is now crucial to conduct comprehensive malware analyses in order to identify and address threats promptly. Through a systematic assessment of state-of-the-art static and dynamic analysis approaches, this study aims to de-obfuscate, reverse-engineer, debug, and sandbox malware samples; identify communication infrastructure; categorize malware families; extract indicators; and grasp dissemination mechanisms. We construct a unified and repeatable malware analysis framework using tools such as IDA Pro, OllyDbg, Process Monitor, Wireshark, and nrdbg. This framework can break through anti-VM and heavily armored malware, hook into hidden processes, intercept system events, trace memory injections, log API calls, and sniff network activity. Fileless delivery chains and self-morphing processes anchored across networks of infected devices impact the filesystem, memory, registry, and native OS resources. Case studies classify popular malware like Dridex, WannaCry, Cerber, Trickbot, Poweliks, and Emotet based on these post-infection payloads. The proposed technique and toolset provide practical forensic analysis of modern exploit kits, worms, sniffers, keyloggers, ransomware, rootkits, and botnets by obstructing points of entry and attack areas on endpoint and network. These steps aid in reducing the scope of existing dangers, curing existing diseases, and warding off potential new ones.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Deep Dive into Malware Analysis and Their Behavior Patterns: A Systematic Technical Review

  • Srishti Singh,
  • Hemraj Shobharam Lamkuche,
  • Devraj Vishnu,
  • Ghassan Samara,
  • H. Azath,
  • Emma Qumsiyeh

摘要

The sophistication of malware attacks is always evolving. To circumvent common countermeasures and take advantage of vulnerabilities, they employ obfuscation, polymorphism effectively and anti-emulation strategies. Consequently, it is now crucial to conduct comprehensive malware analyses in order to identify and address threats promptly. Through a systematic assessment of state-of-the-art static and dynamic analysis approaches, this study aims to de-obfuscate, reverse-engineer, debug, and sandbox malware samples; identify communication infrastructure; categorize malware families; extract indicators; and grasp dissemination mechanisms. We construct a unified and repeatable malware analysis framework using tools such as IDA Pro, OllyDbg, Process Monitor, Wireshark, and nrdbg. This framework can break through anti-VM and heavily armored malware, hook into hidden processes, intercept system events, trace memory injections, log API calls, and sniff network activity. Fileless delivery chains and self-morphing processes anchored across networks of infected devices impact the filesystem, memory, registry, and native OS resources. Case studies classify popular malware like Dridex, WannaCry, Cerber, Trickbot, Poweliks, and Emotet based on these post-infection payloads. The proposed technique and toolset provide practical forensic analysis of modern exploit kits, worms, sniffers, keyloggers, ransomware, rootkits, and botnets by obstructing points of entry and attack areas on endpoint and network. These steps aid in reducing the scope of existing dangers, curing existing diseases, and warding off potential new ones.