PsybOt malware: A step-by-step decompilation case study

PsybOt malware: A step-by-step decompilation case study
复制标题

DOI:
10.1109/wcre.2013.6671321
复制
发表时间:
2013-11
期刊:
2013 20th Working Conference on Reverse Engineering (WCRE)
影响因子:
--
通讯作者:
Lukás Durfina;J. Kroustek;Petr Zemek
Lukás Durfina;J. Kroustek;Petr Zemek
中科院分区:
其他
文献类型:
--
作者:
Lukás Durfina;J. Kroustek;Petr Zemek

文献摘要

被引文献

相似文献

反编译(即反向编译)是逆向工程中最困难和最具挑战性的任务之一。甚至更困难的任务是恶意软件的反编译,因为它通常不遵循标准应用程序二进制接口约定,具有剥离的符号,被混淆,并且可以包含多态代码。此外,近年来,各种智能设备迅速扩展,在许多类型的处理器上运行不同类型的操作系统,并且恶意软件针对这些平台。这些事实,再加上标准反编译工具对特定平台的局限性,意味着在为各种平台反编译恶意软件时需要付出相当大的努力。这是一篇报告真实世界恶意软件反编译的经验论文。我们给出了一个分步的案例研究,通过使用Lissom项目中正在开发的可重定向反编译器来反编译名为psyb0t的MIPS蠕虫。首先,我们详细描述了反编译器。然后,我们提出了案例研究。在此之后,我们分析在反编译过程中获得的结果,并提出我们的个人经验。最后讨论了未来的研究可能性。
Decompilation (i.e. reverse compilation) represents one of the most toughest and challenging tasks in reverse engineering. Even more difficult task is the decompilation of malware because it typically does not follow standard application binary interface conventions, has stripped symbols, is obfuscated, and can contain polymorphic code. Moreover, in the recent years, there is a rapid expansion of various smart devices, running different types of operating systems on many types of processors, and malware targeting these platforms. These facts, combined with the boundedness of standard decompilation tools to a particular platform, imply that a considerable amount of effort is needed when decompiling malware for such a diversity of platforms. This is an experience paper reporting the decompilation of a real-world malware. We give a step-by-step case study of decompiling a MIPS worm called psyb0t by using a retargetable decompiler that is being developed within the Lissom project. First, we describe the decompiler in detail. Then, we present the case study. After that, we analyse the results obtained during the decompilation and present our personal experience. The paper is concluded by discussing future research possibilities.