> For the complete documentation index, see [llms.txt](https://adarshsr.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://adarshsr.gitbook.io/writeups/walk-through/advent-of-cyber-2024/day-6.md).

# Day 6

If I can't find a nice malware to use, I'm not going.

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FQw42A1mmxJGG1mE6tbky%2Fimage.png?alt=media&amp;token=6f367e51-18bd-4e9f-9d73-3834504f0458" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FLgwu65YPn5XBk55Gpm2a%2Fimage.png?alt=media&amp;token=21b5ed55-c4b1-4bf7-97b7-503af153f14a" alt=""><figcaption></figcaption></figure>

Today, we’re diving into **malware analysis**, an essential skill for cybersecurity professionals.

We are testing this malware in a sandbox.

**Sandboxing** is a security practice in which you use an isolated environment, or a “sandbox,” for testing. In a sandbox, you can safely execute and analyze code without risking the integrity of the underlying application, system, or platform.

**YARA** is a tool aimed at (but not limited to) helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families (or whatever you want to describe) based on textual or binary patterns.

Now, let's begin,

Start the machine and wait for it to deploy, today we are working on a windows machine.

We are provided with and run the script named “JingleBells.ps1” in `C:\Tools`. It’s essentially a script that acts as an EDR (Endpoint Detection and Response), continuously monitoring system events and event logs, and notifies us if a registry key is being queried.

* Navigate to the **Tools** directory:

  ```powershell
  cd C:\Tools
  ```
* Execute the EDR script:

  ```powershell
  .\JingleBells.ps1
  ```

This script will monitor all the events.

While keeping the script running, open up file explorer and go to This PC → Local Disk (C:) → Tools → Malware. and execute `MerryChristmas.exe`

This triggers the YARA rules and a popup appears!

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FMwLxDItjoH06i3qiyiB5%2Fimage.png?alt=media&amp;token=1e5c9497-c067-4db4-a0a0-7618fbea8fca" alt=""><figcaption></figcaption></figure>

**Extracting Strings with FLOSS**

We also need to know that there are tools available that extract obfuscated strings from malware binaries. One such tool is **Floss**, a powerful tool developed by Mandiant that functions similarly to the Linux strings tool but is optimized for malware analysis, making it ideal for revealing any concealed details.

Let's try using FLOSS:

Execute the following command :

```powershell
floss.exe C:\Tools\Malware\MerryChristmas.exe | Out-file C:\tools\malstrings.txt
```

* `floss.exe C:\Tools\Malware\MerryChristmas.exe`: This command scans for strings in the binary MerryChrismas.exe. If any hardcoded variables were defined in the malware, Floss should find them.
* The `|` symbol redirects the output of the command in front of it to the input of the command behind it.
* `Out-file C:\tools\malstrings.txt`: We save the command results in a file called `malstrings.txt`.

Navigate to `C:\tools\` and open `malstrings.txt`

Search for the string `THM` using **Ctrl+F**.

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FgT5cFJQAGjqY3xSMAnjI%2Fimage.png?alt=media&amp;token=ac5433e8-90d0-4436-9a3e-6cb863c77bcd" alt=""><figcaption></figcaption></figure>

### Questions

1.What is the flag displayed in the popup window after the EDR detects the malware?

A: **THM{GlitchWasHere}**

2.What is the flag found in the malstrings.txt document after running floss.exe, and opening the file in a text editor?

A: **THM{HiddenClue}**

* Malware analysis involves understanding how malware behaves in sandboxed environments and how it tries to evade detection.
* Tools like **YARA**, **FLOSS** are invaluable for detecting and analyzing malware patterns.

Stay tuned for **Day 7**, and happy hacking! 🎄

***Thank you!***
