Skip to content

Static Disassembly

Static disassembly is a foundational technique in malware analysis, enabling analysts to inspect binary files without executing them. By leveraging tools like Ghidra, defenders can identify entry points, analyze code structure, and detect suspicious patterns that may indicate malicious behavior. This section covers core techniques for static disassembly using Ghidra, including binary loading, entry point identification, and code interpretation.


Opening and Analyzing a Binary

Ghidra automatically performs static analysis when a binary is loaded, identifying functions, data, and control flow. Use the CLI or GUI to open a file:

ghidra -open malware.exe -A x86_64

This command loads malware.exe for 64-bit analysis. Ghidra will parse the binary, reconstructing symbol tables and identifying potential entry points. For PE/ELF files, ensure the architecture matches the target (e.g., x86, x86_64, arm).


Identifying Entry Points

Malware often subverts standard entry points (e.g., main or WinMain), so manual verification is critical. In Ghidra:
1. Navigate to Entry Points in the Symbols window.
2. Look for functions marked as entryPoint or analyze the .text section for code.
3. Use the Graph View to trace execution flow from the initial instruction.

Example:

# CLI: Check entry point address
ghidra -listEntryPoints malware.exe

For custom entry points (e.g., in a DLL), search for GetProcAddress or LoadLibrary calls in the disassembled code.


Interpreting Disassembled Code

Ghidra’s decompiler generates pseudocode, which can reveal obfuscation or malicious logic:
1. API Calls: Look for GetProcAddress, VirtualAlloc, or CreateProcess.
2. Control Flow: Analyze jmp, call, and ret instructions to detect polymorphic behavior.
3. String Analysis: Use the Strings tool to find hardcoded URLs, IPs, or hashes.

Example:

// Decompiled code snippet (simplified)
int main() {
    HMODULE hMod = LoadLibraryA("C:\\Windows\\System32\\calc.exe");
    if (hMod != NULL) {
        typedef int (*Func)();
        Func func = (Func)GetProcAddress(hMod, "WinMain");
        func();
    }
}

This example demonstrates a loader attempting to execute calc.exe, a common red herring in malware.


Advanced Analysis: Cross-Referencing and Decoding

  • Cross-References: Right-click functions to view callers/callees.
  • Decoding Obfuscated Code: Use the Decompiler to resolve XORed or packed sections.
  • Memory Analysis: Inspect .data sections for encrypted payloads or shellcode.

Example:

# CLI: Export disassembled functions to a CSV
ghidra -exportFunctions malware.exe -o output.csv


Key takeaways

  • Static disassembly with Ghidra reveals entry points, API calls, and code structure critical for malware detection.
  • Always verify entry points manually, as malware often bypasses standard loaders.
  • Combine decompiler output with string analysis to identify hardcoded malicious artifacts.
  • Use CLI tools for automation, but rely on the GUI for visualizing control flow and cross-references.
  • Static analysis alone has limitations; integrate with dynamic analysis for comprehensive detection.