Code Monkey home page Code Monkey logo

bsidesroc2022_linux_malware_analysis_course's Introduction

logo

About The Course

According to recent industry reports, Linux focused malware has grown in the past year by over 30%. With the rise in Cloud Computing it’s no surprised that attackers are looking beyond traditional Windows environments to profit off of illicit access. This course was given at BSides Roc 2022 in order to provide students with a broad exposure of techniques and tools to identify, triage and analyze a faux-incident in a CTF style event.

  • A Vagrant file is included in the courses which covers module 01 and 02. Modules 03 and 04 require a GUI, and installing XFCE within the VM caused issues when testing.
  • If you have a Linux VM, simply install Ghidra and Cutter and you'll be good to go.

Note, all files are now included in the git repo itself and you do not need to obtain the malware from the servers listed in the repos.

Disclaimer

These are real modified malware samples! Do NOT run them unless you are absolutely sure of what you are doing! Arch Cloud Labs is not responsible for any damages.

Threat Intel Brieifing on APT-585

Threat Actor(s) APT-585 leverage known exploits and modified offensive security tools to obtain access to victims environments for Cryptocurrency and ransomware attacks. Specifically targeting web servers and vulnerable web applications.

APT-585 leverages leased infrastructure from popular cloud providers to stage capabilities to bring into victims environments. Their leader is unknown, but historically poor opsec has led to the takedown of domains. It's likely their sloppy tactics will lead to revealing themselves.

Special Thanks

Thank you to the Digitial Corpora project for hosting forensic images for forensic education!

 Garfinkel, Farrell, Roussev and Dinolt, Bringing Science to Digital Forensics with Standardized Forensic Corpora, DFRWS 2009, Montreal, Canada.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.