Original title:
Analýza a detekce vysoce obfuskovaných malware hrozeb
Translated title:
Analyzing and Detecting Highly Obfuscated Malware Threats
Authors:
Duchoň, Dávid ; Malinka, Kamil (referee) ; Kolář, Dušan (advisor) Document type: Bachelor's theses
Year:
2025
Language:
slo Publisher:
Vysoké učení technické v Brně. Fakulta informačních technologií Abstract:
[slo][eng]
Táto práca zkúma aké metódy a techniky autori hrozieb používajú. Rieši sa tu ako detekovať takéto hrozby a na aké situácie si treba dať pozor. Pri takýchto hrozbách treba zohľadniť detekčné pravidlo podľa ktorého treba danú rodinu vysoko obfuskovanej malwarovej hrozby detekovať. Najefektívnejšim spôsobom je využitie reverzného inžinierstva s použitím nástrojov na statickú analýzu a dynamickú analýzu. Súčasťou práce je ukážka toho ako taká analýza môže vypadať. Výstupom tejto práce je úspešné detekovanie takýchto hrozieb využitím vytvorených pravidiel v jazyku YARA a následné otestovanie týchto pravidiel na získaných vzorkoch z reálneho sveta.
This thesis explores the methods and techniques used by malware authors. It discusses how to detect these threats and which situations require special attention. For these threats, we need to customize detection rule to effectively detect specific highly obfuscated malware threat family. The most effective approach is the use of reverse engineering, utilizing tools for both static and dynamic analysis. A part of this thesis showcases what such analysis can look like. The outcome of this thesis is the successful detection of these threats using custom rules written in a language called YARA, and the testing of these rules on real-world samples.
Keywords:
crypter; cryptic; detection; dynamic analysis; malware threat; static analysis; YARA
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/253710