Malware analysis combines evidence gathered without execution with behavior observed at runtime. This hands-on course builds that workflow using safe, purpose-built Linux programs so you can learn what file structure, strings, system calls, and library calls reveal about a suspicious executable.
You will identify ELF files, record SHA-256 hashes, inspect headers, extract hardcoded indicators, and trace controlled execution with strace and ltrace. A final black-box challenge asks you to recover a hardcoded key, activate the prepared behavior under tracing, and report the local files it changes.
What You Will Learn
- Determine a binary’s actual type and architecture with
file - Generate a SHA-256 fingerprint and inspect ELF headers with
readelf - Extract and filter embedded strings for URLs, IP addresses, and hardcoded secrets
- Capture complete system-call traces and narrow them to file and network activity with
strace - Interpret
openat,unlink,socket, andconnectevidence from controlled execution - Trace shared-library functions with
ltraceand isolate string and file-handling calls - Recover a prepared plaintext payload before it is transformed and written to disk
- Combine static clues with dynamic traces to document triggered file modifications
Who This Course Is For
This intermediate course is for cybersecurity learners, incident responders, Linux administrators, and aspiring malware analysts who want a practical introduction to executable triage. It emphasizes observable behavior and evidence collection rather than assembly-level reverse engineering.
Prerequisites: Comfort using a Linux terminal, reading files, filtering text with grep, and redirecting output. Basic familiarity with processes, executables, networking, and hashes is helpful; C programming and disassembly experience are not required.
Learning environment: An interactive Ubuntu 22.04 terminal with file, SHA-256 utilities, readelf, strings, strace, and ltrace. All samples are harmless C programs compiled specifically for the labs and operate only on prepared local files and test indicators.
Frequently Asked Questions
Will I execute real malware?
No. Every executable is a purpose-built simulator whose source is created during lab setup. The programs demonstrate file, network-call, credential, and payload-handling patterns without containing real malware capabilities.
Is the lab isolation suitable for analyzing unknown samples of my own?
No. The LabEx environment is appropriate for the supplied harmless samples, but the course does not configure a hardened malware sandbox, network containment, snapshots, or monitoring controls for arbitrary untrusted binaries. Do not upload or run your own unknown samples here.
Does this course teach disassembly or decompilation?
No. Despite the final challenge’s reverse-engineering theme, the practical scope is black-box triage with file metadata, ELF headers, strings, strace, and ltrace. Assembly, debuggers, decompilers, unpacking, and code reconstruction are outside the scope.
Are external threat-intelligence services required?
No. You record hashes and local indicators but do not upload samples or query VirusTotal or other public services. All conclusions come from the supplied artifacts and trace output.


