Empowering Malware Analysis with IDA AppCall

sbc-vn 3,340 views 61 slides Oct 03, 2024
Slide 1
Slide 1 of 61
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37
Slide 38
38
Slide 39
39
Slide 40
40
Slide 41
41
Slide 42
42
Slide 43
43
Slide 44
44
Slide 45
45
Slide 46
46
Slide 47
47
Slide 48
48
Slide 49
49
Slide 50
50
Slide 51
51
Slide 52
52
Slide 53
53
Slide 54
54
Slide 55
55
Slide 56
56
Slide 57
57
Slide 58
58
Slide 59
59
Slide 60
60
Slide 61
61

About This Presentation

Empowering Malware Analysis
with IDA AppCall


Slide Content

Empowering Malware Analysis
with IDA AppCall
m4n0w4r
10/1/2024 1
#Security_Bootcamp_2024 #Phú_Quốc

#Wh0_4m_1?
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 2

What we will cover



10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 3

Summary of Appcall in IDA (1)




10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 4

Summary of Appcall in IDA (2)




10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 5

A simple example (1)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 6

A simple example (2)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 7

A simple example (3)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 8

A Great Explanation Video
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 9

Quote Of The Day
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 10

LOKIBOT
10/1/2024 11

LokiBot (1)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 12

LokiBot (2)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 13

Our analysis
Reversing
LokiBot
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 14

LokiBot Infection Chain
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 15

Dynamic Resolve API Functions
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 16

Hardcore Reverser –try hard to understand logic
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 17

Hardcore Reverser –reimplement code
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 18

Extreme Reverser –try to find lazy way



10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 19

Recover API Name with IDA AppCall (1)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 20

Recover API Name with IDA AppCall (2)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 21

Recover API Name with IDA AppCall (3)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 22

Recover API Name with IDA AppCall (4)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 23

Result
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 24

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 25

Our analysis
EMOTET
10/1/2024 26

For those who don’t know (1)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 27

For those who don’t know (2)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 28

For those who don’t know (3)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 29

For those who don’t know (4)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 30

For those who don’t know (5)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 31

For those who don’t know (6)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 32

For those who don’t know (7)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 33

And Meme Everywhere…
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 34

For those who don’t know (8)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 35

From “Dong Lao” with Love
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 36

From “Dong Lao” with Love
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 37

Our analysis
Reversing
Emotet
10/1/2024 38

Reversing Engineering Emotet
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 39

Context (1)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 40

Context (2)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 41

Decrypt Strings

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 42

Decrypt Strings (1)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 43

Decrypt Strings (2)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 44

Decrypt Strings (3) (Pseudocode)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 45

Decrypt Strings (4) (Verify)


10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 46

Decrypt Strings (5) (Solution?)


•
•
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 47

Recover Original Strings with IDA AppCall(1)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 48

Recover Original Strings with IDA AppCall(2)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 49

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 50

Extract C2s Configuration (1)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 51

Extract C2s Configuration (2)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 52

Extract C2s Configuration (3)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 53

Extract C2s Configuration (4)
• 
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 54

Automate Extract C2s using IDA AppCall(1)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 55

Automate Extract C2s using IDA AppCall(2)

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 56

Automate Extract C2s using IDA AppCall(3)
10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 57

10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 58

Resources









10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 59

Resources








10/1/2024 Empowering Malware Analysis with IDA AppCall Feature 60

End…
10/1/2024 61