Classify Malware with YARA

Classify Malware with YARA

Source: YouTube · John Hammond · published Sep 13, 2023 · 25:23

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

This video introduces YARA, a pattern-matching tool aimed at helping malware researchers and cybersecurity practitioners identify and classify samples based on text or binary signatures 1:13.

Key Takeaways:
• YARA rules consist of strings (text, hex, or regex) and boolean conditions, allowing users to create descriptions for malware families or specific file types like PE or ELF 4:05 8:20.
• Users can leverage actively maintained public repositories, such as Florian Roth's signature base, to access existing threat intelligence rules rather than writing everything from scratch 12:48.
• Practical applications include recursively scanning directories for specific indicators, such as Discord webhooks, or analyzing malicious packages linked to groups like Lazarus 13:56 15:20.
• Advanced integration is possible through Yara-Python for automation and retro hunting on platforms like VirusTotal and Malware Bazaar to detect threats across historical data 17:46.

Ultimately, YARA serves as a versatile "Swiss Army knife" for threat hunting, enabling professionals to efficiently organize and analyze malware collections.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

I have a collection of malware. No, seriously. I have this big pile of malware samples that I've collected over the years and I keep adding to and you probably have one, too. Or at the very least, you totally should. Especially if you're a cyber security practitioner, whether or not you're an analyst in a security operation center or a researcher or anyone just part of the field. Malware is something crazy cool to get into. The question is though, how do you classify that malware? Whether you receive it, I don't know, through a feed, through your sock, or your seam, or you just have a big boatload of malware like I do, you can use one incredible tool and kind of a whole language to be able to match on malware samples based off a given criteria. Let's dive into Yara. Now, I know, look, I'm …