\documentclass[10pt,a4paper]{article} % Packages \usepackage{fancyhdr} % For header and footer \usepackage{multicol} % Allows multicols in tables \usepackage{tabularx} % Intelligent column widths \usepackage{tabulary} % Used in header and footer \usepackage{hhline} % Border under tables \usepackage{graphicx} % For images \usepackage{xcolor} % For hex colours %\usepackage[utf8x]{inputenc} % For unicode character support \usepackage[T1]{fontenc} % Without this we get weird character replacements \usepackage{colortbl} % For coloured tables \usepackage{setspace} % For line height \usepackage{lastpage} % Needed for total page number \usepackage{seqsplit} % Splits long words. %\usepackage{opensans} % Can't make this work so far. Shame. Would be lovely. \usepackage[normalem]{ulem} % For underlining links % Most of the following are not required for the majority % of cheat sheets but are needed for some symbol support. \usepackage{amsmath} % Symbols \usepackage{MnSymbol} % Symbols \usepackage{wasysym} % Symbols %\usepackage[english,german,french,spanish,italian]{babel} % Languages % Document Info \author{yolk} \pdfinfo{ /Title (reverse-engineering-malware.pdf) /Creator (Cheatography) /Author (yolk) /Subject (Reverse-Engineering Malware Cheat Sheet) } % Lengths and widths \addtolength{\textwidth}{6cm} \addtolength{\textheight}{-1cm} \addtolength{\hoffset}{-3cm} \addtolength{\voffset}{-2cm} \setlength{\tabcolsep}{0.2cm} % Space between columns \setlength{\headsep}{-12pt} % Reduce space between header and content \setlength{\headheight}{85pt} % If less, LaTeX automatically increases it \renewcommand{\footrulewidth}{0pt} % Remove footer line \renewcommand{\headrulewidth}{0pt} % Remove header line \renewcommand{\seqinsert}{\ifmmode\allowbreak\else\-\fi} % Hyphens in seqsplit % This two commands together give roughly % the right line height in the tables \renewcommand{\arraystretch}{1.3} \onehalfspacing % Commands \newcommand{\SetRowColor}[1]{\noalign{\gdef\RowColorName{#1}}\rowcolor{\RowColorName}} % Shortcut for row colour \newcommand{\mymulticolumn}[3]{\multicolumn{#1}{>{\columncolor{\RowColorName}}#2}{#3}} % For coloured multi-cols \newcolumntype{x}[1]{>{\raggedright}p{#1}} % New column types for ragged-right paragraph columns \newcommand{\tn}{\tabularnewline} % Required as custom column type in use % Font and Colours \definecolor{HeadBackground}{HTML}{333333} \definecolor{FootBackground}{HTML}{666666} \definecolor{TextColor}{HTML}{333333} \definecolor{DarkBackground}{HTML}{A3A3A3} \definecolor{LightBackground}{HTML}{F3F3F3} \renewcommand{\familydefault}{\sfdefault} \color{TextColor} % Header and Footer \pagestyle{fancy} \fancyhead{} % Set header to blank \fancyfoot{} % Set footer to blank \fancyhead[L]{ \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{C} \SetRowColor{DarkBackground} \vspace{-7pt} {\parbox{\dimexpr\textwidth-2\fboxsep\relax}{\noindent \hspace*{-6pt}\includegraphics[width=5.8cm]{/web/www.cheatography.com/public/images/cheatography_logo.pdf}} } \end{tabulary} \columnbreak \begin{tabulary}{11cm}{L} \vspace{-2pt}\large{\bf{\textcolor{DarkBackground}{\textrm{Reverse-Engineering Malware Cheat Sheet}}}} \\ \normalsize{by \textcolor{DarkBackground}{yolk} via \textcolor{DarkBackground}{\uline{cheatography.com/201571/cs/42678/}}} \end{tabulary} \end{multicols}} \fancyfoot[L]{ \footnotesize \noindent \begin{multicols}{3} \begin{tabulary}{5.8cm}{LL} \SetRowColor{FootBackground} \mymulticolumn{2}{p{5.377cm}}{\bf\textcolor{white}{Cheatographer}} \\ \vspace{-2pt}yolk \\ \uline{cheatography.com/yolk} \\ \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Cheat Sheet}} \\ \vspace{-2pt}Published 10th March, 2024.\\ Updated 10th March, 2024.\\ Page {\thepage} of \pageref{LastPage}. \end{tabulary} \vfill \columnbreak \begin{tabulary}{5.8cm}{L} \SetRowColor{FootBackground} \mymulticolumn{1}{p{5.377cm}}{\bf\textcolor{white}{Sponsor}} \\ \SetRowColor{white} \vspace{-5pt} %\includegraphics[width=48px,height=48px]{dave.jpeg} Measure your website readability!\\ www.readability-score.com \end{tabulary} \end{multicols}} \begin{document} \raggedright \raggedcolumns % Set font size to small. Switch to any value % from this page to resize cheat sheet text: % www.emerson.emory.edu/services/latex/latex_169.html \footnotesize % Small font. \begin{multicols*}{2} \begin{tabularx}{8.4cm}{p{0.8 cm} p{0.8 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{GENERAL APPROACH}} \tn % Row 0 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Set up a controlled, isolated laboratory in which to examine the malware specimen.} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{Perform behavioral analysis to examine the specimen's interactions with its environment.} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Perform static code analysis to further understand the specimen's inner-workings.} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{Perform dynamic code analysis to understand the more difficult aspects of the code.} \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{If necessary, unpack the specimen.} \tn % Row Count 9 (+ 1) % Row 5 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{Repeat steps 2, 3, and 4 (order may vary) until analysis objectives are met.} \tn % Row Count 11 (+ 2) % Row 6 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Document findings and clean-up the laboratory for future analysis. BEHAVIORAL ANALYSIS} \tn % Row Count 13 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{6.08 cm} x{1.92 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{IDA PRO FOR STATIC CODE ANALYSIS}} \tn % Row 0 \SetRowColor{LightBackground} Text search & Alt+T \tn % Row Count 1 (+ 1) % Row 1 \SetRowColor{white} Show strings window & \seqsplit{Shift+F12} \tn % Row Count 2 (+ 1) % Row 2 \SetRowColor{LightBackground} Show operand as hex value & Q \tn % Row Count 3 (+ 1) % Row 3 \SetRowColor{white} Insert comment & : \tn % Row Count 4 (+ 1) % Row 4 \SetRowColor{LightBackground} Follow jump or call in view & Enter \tn % Row Count 5 (+ 1) % Row 5 \SetRowColor{white} Return to previous view & Esc \tn % Row Count 6 (+ 1) % Row 6 \SetRowColor{LightBackground} Go to next view & \seqsplit{Ctrl+Enter} \tn % Row Count 8 (+ 2) % Row 7 \SetRowColor{white} Show names window & Shift+F4 \tn % Row Count 9 (+ 1) % Row 8 \SetRowColor{LightBackground} Display function's flow chart & F12 \tn % Row Count 10 (+ 1) % Row 9 \SetRowColor{white} Display graph of function calls & Ctrl+F12 \tn % Row Count 12 (+ 2) % Row 10 \SetRowColor{LightBackground} Go to program's entry point & Ctrl+E \tn % Row Count 13 (+ 1) % Row 11 \SetRowColor{white} Go to specific address & G \tn % Row Count 14 (+ 1) % Row 12 \SetRowColor{LightBackground} Rename a variable or function & N \tn % Row Count 15 (+ 1) % Row 13 \SetRowColor{white} Show listings of name & Ctrl+L \tn % Row Count 16 (+ 1) % Row 14 \SetRowColor{LightBackground} Display listing of segments & Ctrl+S \tn % Row Count 17 (+ 1) % Row 15 \SetRowColor{white} Show stack of current function & Ctrl+K \tn % Row Count 18 (+ 1) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{p{0.8 cm} p{0.8 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{BYPASSING MALWARE DEFENSES}} \tn % Row 0 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{To try unpacking quickly, infect the system and dump from memory via LordPE or OllyDump.} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{For more surgical unpacking, locate the Original Entry Point (OEP) after the unpacker executes.} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{If you can't unpack cleanly, examine the packed specimen via dynamic code analysis while it runs.} \tn % Row Count 6 (+ 2) % Row 3 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{When unpacking in OllyDbg, try SFX (bytewise) and OllyDump's "Find OEP by Section Hop".} \tn % Row Count 8 (+ 2) % Row 4 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Conceal OllyDbg via HideOD and OllyAdvanced.} \tn % Row Count 9 (+ 1) % Row 5 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{A JMP or CALL to EAX may indicate the OEP, possibly preceded by POPA or POPAD.} \tn % Row Count 11 (+ 2) % Row 6 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Look out for tricky jumps via SEH, RET, CALL, etc.} \tn % Row Count 12 (+ 1) % Row 7 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{If the packer uses SEH, anticipate OEP by tracking stack areas used to store the packers' handlers.} \tn % Row Count 14 (+ 2) % Row 8 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Decode protected data by examining results of the decoding function via dynamic code analysis.} \tn % Row Count 16 (+ 2) % Row 9 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{Correct PE header problems with XPELister, LordPE, ImpREC, PEID, etc.} \tn % Row Count 18 (+ 2) % Row 10 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{To get closer to OEP, try breaking on unpacker's calls to LoadLibraryA or GetProcAddress.} \tn % Row Count 20 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{p{0.8 cm} p{0.8 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{BEHAVIORAL ANALYSIS}} \tn % Row 0 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Be ready to revert to good state via dd, VMware snapshots, CoreRestore, Ghost, SteadyState, etc.} \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{Monitor local (Process Monitor, Process Explorer) and network (Wireshark, tcpdump) interactions.} \tn % Row Count 4 (+ 2) % Row 2 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Detect major local changes (RegShot, Autoruns).} \tn % Row Count 5 (+ 1) % Row 3 \SetRowColor{white} \mymulticolumn{2}{x{8.4cm}}{Redirect network traffic (hosts file, DNS, Honeyd).} \tn % Row Count 7 (+ 2) % Row 4 \SetRowColor{LightBackground} \mymulticolumn{2}{x{8.4cm}}{Activate services (IRC, HTTP, SMTP, etc.) as needed to evoke new behavior from the specimen.} \tn % Row Count 9 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{x{5.68 cm} x{2.32 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{OLLYDBG FOR DYNMAIC CODE ANALYSIS}} \tn % Row 0 \SetRowColor{LightBackground} Step into instruction & F7 \tn % Row Count 1 (+ 1) % Row 1 \SetRowColor{white} Step over instruction & F8 \tn % Row Count 2 (+ 1) % Row 2 \SetRowColor{LightBackground} Execute till next breakpoint & F9 \tn % Row Count 3 (+ 1) % Row 3 \SetRowColor{white} Execute till next return & Ctrl+F9 \tn % Row Count 4 (+ 1) % Row 4 \SetRowColor{LightBackground} Show previous/next executed instruction & - / + \tn % Row Count 6 (+ 2) % Row 5 \SetRowColor{white} Return to previous view & * \tn % Row Count 7 (+ 1) % Row 6 \SetRowColor{LightBackground} Show memory map & Alt+M \tn % Row Count 8 (+ 1) % Row 7 \SetRowColor{white} Follow expression in view & Ctrl+G \tn % Row Count 9 (+ 1) % Row 8 \SetRowColor{LightBackground} Insert comment & ; \tn % Row Count 10 (+ 1) % Row 9 \SetRowColor{white} Follow jump or call in view & Enter \tn % Row Count 11 (+ 1) % Row 10 \SetRowColor{LightBackground} Show listings of names & Ctrl+N \tn % Row Count 12 (+ 1) % Row 11 \SetRowColor{white} New binary search & Ctrl+B \tn % Row Count 13 (+ 1) % Row 12 \SetRowColor{LightBackground} Next binary search result & Ctrl+L \tn % Row Count 14 (+ 1) % Row 13 \SetRowColor{white} Show listing of software breakpoints & Alt+B \tn % Row Count 16 (+ 2) % Row 14 \SetRowColor{LightBackground} Assemble Instruction & Space \tn % Row Count 17 (+ 1) % Row 15 \SetRowColor{white} Edit data in memory & Ctrl+E \tn % Row Count 18 (+ 1) % Row 16 \SetRowColor{LightBackground} Show SEH chain & View \textgreater{} SEH chain \tn % Row Count 20 (+ 2) % Row 17 \SetRowColor{white} Show patches & Ctrl+P \tn % Row Count 21 (+ 1) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} \begin{tabularx}{8.4cm}{p{1.04 cm} x{6.96 cm} } \SetRowColor{DarkBackground} \mymulticolumn{2}{x{8.4cm}}{\bf\textcolor{white}{COMMON X86 REGISTERS AND USES}} \tn % Row 0 \SetRowColor{LightBackground} EAX & Addition, Multiplication, Function Results \tn % Row Count 2 (+ 2) % Row 1 \SetRowColor{white} ECX & Counter \tn % Row Count 3 (+ 1) % Row 2 \SetRowColor{LightBackground} EBP & Base for referencing function arguments and local variables. \tn % Row Count 5 (+ 2) % Row 3 \SetRowColor{white} ESP & Points to the current "top" of the stack; changes via Push, Pop, and more. \tn % Row Count 8 (+ 3) % Row 4 \SetRowColor{LightBackground} \seqsplit{EFLAGS} & Contains flags that store outcomes of computations. \tn % Row Count 10 (+ 2) \hhline{>{\arrayrulecolor{DarkBackground}}--} \end{tabularx} \par\addvspace{1.3em} % That's all folks \end{multicols*} \end{document}