DerbyCon 7.0 & Tyler Hudak's Intro to Malware Analysis





https://www.derbycon.com/wp-content/uploads/2017/03/cropped-2000.png
Copyright DerbyCon 2017

DerbyCon VII: Legacy

DerbyCon VII: Legacy just ended, and I have to say, it surpassed last year's experience.  Now, I'm pretty new to the professional infosec world having just accepted my current job in August of 2016.  Like most people in infosec will claim, I am an introvert, so meeting people is a rather daunting task. 

One of the things I like to do being new to the professional infosec world is follow a few of the more prominent people on Twitter.  This led me to following Lesley (@hacks4pancakes), as well as Dave Kennedy (@HackingDave), who is the founder of DerbyCon.  Lesley posted a tweet asking for volunteers for the Root Beer Float social that took place on Saturday.  Determined to meet more people, I volunteered, and met a great group of individuals.

The DerbyCon 7.0 Root Beer Float Crew!



I even gathered up the courage to meet Dave, who is a wonderful, humble, and caring individual (thanks for the picture Dave!).

The DerbyCon event, for those who haven't attended, is a 3 day conference with hackers, presentations, ctf challenges, vendors, and a lot of booze.  There is always something to do, and you are guaranteed to learn something new.  I think the beauty of this Con is that everyone is very inclusive, willing to go out of their way to help you, and it really does feel like a tight-knit family.

I arrived Tuesday evening to prepare for my training class, Introduction to malware Analysis, which I have reviewed below.  Over Wednesday and Thursday, I dove head first into a somewhat familiar world of malware analysis. 

Those days flew by quickly, and Friday arrived (as did hundreds of people ready to have some fun).  I opened my DerbyCon with a visit to the Hardware Hacking Village first thing in the morning to learn from the beard and PCB board master @Blenster how to solder (I made the 6-LED DerbyCon VII blinky badge).  First hour of the Con and I already learned something new and bought more kits online.  I then went to a couple of talks, tried my hand at the CTF (as I did during DerbyCon VI), and attended the "Women in Tech" panel in SEVillage.  That talk was very enlightening to me being a white male in infosec.  I think everyone should attend a talk on the gender gap issue and double standards in infosec.

Saturday came, and I ended up getting another badge from the Hardware Hacking Village to take home and do on my own (why not?).  I didn't attend nearly as many talks on Saturday as I wanted to focus on the CTF a little bit more.  The CTF is a great, albeit frustrating time, put one by a couple of individuals.  As I'm going to be taking my OSCP training/exam in the near future, I figured I should give it a shot.  The overall lesson I learned was that I still have a lot to learn (single member team, so I don't have any real hope in getting the coveted Black Badge that the teams of 5-8 people are in the running for).  Still, a good time, and a humbling experience.

The final day of the Con arrived and I found myself not feeling 100%.  Whether it was the long week and meeting people, or just lack of sleep catching up to me, I decided to leave the Con behind a bit early in the morning.  The memories I have from this Con though, will be with me for a lifetime.

Review - Introduction to Malware Analysis

I took the opportunity to sign up for Introduction to Malware Analysis, taught by Tyler Hudak (@SecShoggoth), during this DerbyCon.  My previous experience with malware analysis was looking at a ransomware-dropper macro-enabled word document.  That experience however was limited to dynamic analysis of "let's just open the document, view the macros, and see what it is doing".  When I downloaded the exe, I ran strings, found nothing of use, and ran it...then I discovered it was ransomware.

Enter Tyler's training.  I researched the training options before training ticket sales opened up, and thought Malware Analysis would prove the most beneficial for my career and my company.  Therefore, I started looking into the instructor.  It was obvious I made the right choice just from his Twitter posts on board games and other RPGs (I am a fan of both).

Arriving to the class 8am Wednesday morning, I took a seat right in the middle of the room, setup my "old" (5+ years) laptop, and waited for the class to begin.  Tyler opened with his credentials - an impressive length of time in the infosec world, and even more so with just teaching the course.  Tyler's training covered a couple of topics related to malware analysis, but it could really be boiled down into 3 major sections (for me):
  1. Malware Analysis Lab Setup, definitions, classifications
  2. Static Analysis
  3. Dynamic Analysis
As we started out the sections of Static and Dynamic Analysis, you could tell that Tyler really enjoys what he does.  His enthusiasm came through as he discussed each topic, and even more so when people would ask questions relating to the content.

His course comes with a fully-baked lab manual including tools, malware samples, lab questions, and lab answers.  This was amazing because I could take everything home and continue looking at the tools we didn't cover during the course.

Overall, the course definitely gave me a large amount of new tools to use when a sample comes into my environment, and, more importantly, gave me a thought process to approach each sample with (i.e., what type of malware, what is it doing on the machine, what is it doing on the network, is there anything exposed in strings, is it packed or encrypted).  Looking at malware analysis more as a puzzle greatly increases my desire to get more in-depth with it, and I wouldn't have thought about it that way had Tyler not taught me all of the fun to be had in reversing and analyzing malware.

I would strongly recommend taking Tyler's course if you are wanting to get into Malware Analysis - you will not regret it!




Comments

Popular posts from this blog

Prepping for OSCP: Walkthrough for LazySysAdmin

Retrospective on the OSCP Exam