Malware Analysis Of Malicious Documents

A Beginner's Course on Analyzing Malicious PDF and Microsoft Office Documents Using Remnux and Windows Virtual Machines

   Watch Promo

What you'll learn

  • Analyzing Malicious Documents
  • Analyzing Malicious PDF documents
  • Analyzing Malicious Microsoft documents
  • Install Remnux Virtual Machine
  • Extracting document Meta-Data
  • Basic Linux Commands Used in Malware Analysis
  • Extracting Embedded Objects and Javascript from PDF documents
  • Extracting VBA Macro Scripts from Office Documents
  • De-obfuscating Javascript and VBA scripts
  • Automating Analysis of Documents
  • Viewing and Debugging Malicious Office Macros
  • Identifying Maker and Origin of Malicious Documents
  • Using Yara to Identify Malicious Patterns and Signatures
  • Analyzing Open Office XML Format Documents
  • Analyzing Structured Storage Format Documents
  • Estimating age and date of document creation
  • Analyzing powershell scripts
  • Detecting Malware Artifacts and Indicators of Compromise
  • and more...

Requirements

  • Windows PC
  • Interest in Malware Analysis
  • Basic Linux knowledge helpful but not strictly necessary

Description

Did you know that you could infect your computer just by opening a pdf or microsoft office document? If that came as a shocker for you then you need to take this course. Documents are one of the main vector of attacks for malware authors because of their widespread use. Everyone uses documents to create reports, memos and articles. In fact everything we do for communication involves the use of documents. That is why this is a very popular way to infect computers. Documents are used as the first stage of a malware attack. Embedded in documents are scripts that will download a second stage payload consisting of additional malware, eg ransomware, remote access tools and more.

In this course, you will learn how to check and analyze malicious pdf and office documents for signs of malicious artifacts and indicators of compromise. This is a beginners course and targeted to those who are absolutely new to this field. I will take you from zero to proficient level in analyzing malicious documents. You will learn using plenty of practical walk-throughs. We will learn the basic knowledge and skills in analyzing documents. All the needed tools and where to download them will be provided. By the end of this course, you will have the fundamentals of malware analysis of documents under your belt to further your studies in this field. Even if you do not intend to take up malware analysis as a career, still the knowledge and skills gained would enable you to check documents for dangers and protect yourself from these attacks.

We will use remnux and windows virtual machine. Remnux is a Debian-based linux distribution that contains all the necessary tools for malware analysis. Some background on linux would be helpful but not strictly necessary. We will also install document debuggers in a windows virtual machine. Then, I will show you how to get started with the very basic tools in remnux and windows. All the essential theory will be covered but kept to the minimum. The emphasis is on practicals and lab exercises.

Go ahead and enroll now and I will see you inside.

Who this course is for:

  • Beginners to Malware Analysis
  • Students embarking on career path to become Malware Analysts
  • Anyone eager to learn how to know if a document is malicious


Your Instructor


Paul Chin
Paul Chin

I am a semi-retired college lecturer with more than 20 years experience in teaching computing and information technology. My interests range from reversing, coding to graphics design, apps, games development, music, health, spirituality and well-being. In my spare time, I also play the piano and keyboard. I enjoy teaching face-to-face and online and also love educating and inspiring others to succeed and live the life of their dreams.


Join Today & Get Access To This Course & Every Resource You Need Grow Your Cyber Skills & Advance Your Career. Beginner & Expert Training.

Course Curriculum


  Section 1 : Introduction
Available in days
days after you enroll
  Section 3 : Malware Analysis Process
Available in days
days after you enroll
  Section 6 : Performing Javascript Analysis
Available in days
days after you enroll
  Section 7 : Lab: Pdf Analysis
Available in days
days after you enroll
  Section 9 : Performing VBA Script Analysis
Available in days
days after you enroll
  Section 12 : Resources For Further Study
Available in days
days after you enroll

Frequently Asked Questions


When does the course start and finish?
The course starts now and never ends! It is a completely self-paced online course - you decide when you start and when you finish.
How long do I have access to the course?
How does lifetime access sound? After enrolling, you have unlimited access to this course for as long as you like - across any and all devices you own.
What if I am unhappy with the course?
We would never want you to be unhappy! If you are unsatisfied with your purchase, contact us in the first 30 days and we will give you a full refund.

Become A Member And Unlock Unlimited Access To This Course Plus Over 30,000+ Top Cyber Security Classes, Virtual Labs, Practice Tests, And Exam Simulations.

Designed To Help You Expand Your Skill Set And Propel Your Career Forward. Whether You're Just Starting Out Or You're An Industry Expert, There's Something Here For Everyone. Let's Grow Together!