MALWARE-ANALYSIS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Practical guide to setting up a malware analysis lab and performing static and dynamic analysis safely.
SAFE LAB SETUP#
Option 1: FlareVM (Windows Analysis)
Requirements: Windows 10/11 VM, 4GB+ RAM, 60GB+ disk
Install:
1. Fresh Windows VM (disable Windows Update)
2. Snapshot clean state
3. Open PowerShell as Admin:
Set-ExecutionPolicy Unrestricted -Force
(New-Object net.webclient).DownloadFile(
'https://raw.githubusercontent.com/mandiant/flare-vm/main/install.ps1',
"$env:USERPROFILE\Desktop\install.ps1")
Unblock-File "$env:USERPROFILE\Desktop\install.ps1"
& "$env:USERPROFILE\Desktop\install.ps1"
4. Wait for installation (1-2 hours)
5. Snapshot "FlareVM-Ready"
Includes: x64dbg, PEStudio, Ghidra, IDA Free, Process Monitor,
Wireshark, Python, YARA, and 200+ tools
Option 2: REMnux (Linux Analysis)
Requirements: Ubuntu-based VM, 4GB+ RAM, 60GB+ disk
Install:
wget https://REMnux.org/remnux-cli
chmod +x remnux-cli
sudo mv remnux-cli /usr/local/bin/remnux
sudo remnux install --mode=full
Includes: radare2, Ghidra, YARA, ClamAV, oledump, oletools,
pdfparser, peframe, binwalk, Wireshark, inetsim
Network Isolation:
- Use Host-Only or Internal network in VMware/VirtualBox
- INetSim on REMnux to simulate internet services
- FakeDNS for DNS simulation
- Configure: sudo inetsim --config /etc/inetsim/inetsim.conf
- Never analyze malware on host or production network
Snapshot Strategy:
1. Clean OS install
2. Tools installed (FlareVM/REMnux ready)
3. Pre-analysis (revert here before each sample)
STATIC ANALYSIS - INITIAL TRIAGE#
File identification:
file sample.exe # file type identification
file sample.dll
exiftool sample.exe # metadata extraction
Hashing:
md5sum sample.exe
sha256sum sample.exe
ssdeep sample.exe # fuzzy hash for similarity
# Check hash on VirusTotal
curl -s "https://www.virustotal.com/api/v3/files/<SHA256>" \
-H "x-apikey: <YOUR_API_KEY>"
Strings extraction:
strings sample.exe # ASCII strings
strings -el sample.exe # Unicode (little-endian)
strings sample.exe | grep -i "http\|https\|ftp\|www" # URLs
strings sample.exe | grep -iE "\b[A-Za-z0-9._%+-]+@" # emails
strings sample.exe | grep -iE "([0-9]{1,3}\.){3}[0-9]" # IPs
strings sample.exe | grep -i "password\|key\|token\|secret"
strings sample.exe | grep -i "cmd\|powershell\|wscript"
# FLOSS (FLARE Obfuscated String Solver) - finds encoded strings
floss sample.exe
floss --no-static-strings sample.exe # only decoded strings
PE Analysis (Windows executables):
PEStudio:
- GUI tool on FlareVM
- Shows imports, sections, resources, signatures
- Highlights suspicious indicators
- Checks against VirusTotal
pestudio (CLI):
pestudio sample.exe
pefile (Python):
import pefile
pe = pefile.PE('sample.exe')
print(pe.FILE_HEADER.TimeDateStamp) # compilation timestamp
for section in pe.sections:
print(section.Name, hex(section.VirtualAddress),
section.SizeOfRawData, section.get_entropy())
for entry in pe.DIRECTORY_ENTRY_IMPORT:
print(entry.dll)
for imp in entry.imports:
print(f" {imp.name}")
Detect It Easy (DIE):
- Identifies packers, compilers, protectors
- Shows entropy graph (high entropy = packed/encrypted)
- Detects UPX, Themida, VMProtect, custom packers
CFF Explorer:
- PE header viewer and editor
- Import/export table analysis
- Resource viewer
Packer detection and unpacking:
# Entropy check (>7.0 suggests packing)
python3 -c "
import pefile, math
pe = pefile.PE('sample.exe')
for s in pe.sections:
print(f'{s.Name.decode().strip(chr(0)):8s} entropy: {s.get_entropy():.2f}')
"
# UPX unpacking
upx -d sample.exe -o sample_unpacked.exe
# For custom packers: dynamic unpacking with x64dbg
# Set breakpoint on VirtualAlloc/VirtualProtect, dump unpacked PE
Document analysis:
# Office documents
olevba sample.docm # extract VBA macros
oledump.py sample.doc # OLE stream analysis
oledump.py -s <stream_num> -v sample.doc # dump specific stream
# PDF analysis
pdfparser.py sample.pdf
pdfparser.py --search javascript sample.pdf
pdf-parser.py -f sample.pdf # filter suspicious
peepdf -f sample.pdf # interactive analysis
STATIC ANALYSIS - DEEPER DIVE#
Disassembly / Decompilation:
Ghidra (free, NSA):
- Import binary, auto-analyze
- CodeBrowser for disassembly + decompilation
- Function graph view for control flow
- Cross-references (Ctrl+Shift+F)
- Script manager for automation
IDA Free:
- Industry standard disassembler
- Free version: x86/x64 cloud decompiler
- Graph view, proximity view
- Rename functions and variables for clarity
radare2 / Cutter:
r2 -A sample.exe # analyze all
afl # list functions
s main; pdf # seek to main, print disassembly
VV # visual graph mode
Binary Ninja (commercial):
- Modern UI, HLIL/MLIL/LLIL
- Good API for scripting
DYNAMIC ANALYSIS - BEHAVIORAL#
Process Monitor (ProcMon):
- Filter by process name: sample.exe
- Capture: file system, registry, network, process activity
- Key filters:
Operation is WriteFile
Operation is RegSetValue
Operation is TCP Connect
Operation is Process Create
- Save as CSV/PML for analysis
Process Explorer:
- Real-time process tree
- DLL list per process
- Handle viewer
- VirusTotal integration
- Verify image signatures
API Monitor:
- Hook and log API calls
- Filter by category (file, registry, network, crypto)
- Useful for understanding malware behavior
Wireshark / tshark:
# Capture during execution
wireshark -i eth0 -k -w capture.pcap
# Filter C2 traffic
tshark -r capture.pcap -Y "dns" -T fields -e dns.qry.name
tshark -r capture.pcap -Y "http.request" -T fields -e http.host -e http.request.uri
tshark -r capture.pcap -Y "tls.handshake.extensions_server_name" \
-T fields -e tls.handshake.extensions_server_name
Regshot:
- Take snapshot before execution (1st shot)
- Run malware
- Take snapshot after (2nd shot)
- Compare: shows registry and file changes
DYNAMIC ANALYSIS - DEBUGGING#
x64dbg (Windows):
Key shortcuts:
F2 - Set breakpoint
F7 - Step into
F8 - Step over
F9 - Run
Ctrl+G - Go to address/expression
Common breakpoints for malware:
CreateFileA/W # file operations
WriteFile # file writes
RegSetValueExA/W # registry modifications
InternetOpenA/W # network initialization
HttpSendRequestA/W # HTTP requests
WSAStartup # Winsock init
connect # network connections
VirtualAlloc # memory allocation (unpacking)
VirtualProtect # memory permission change
CreateProcessA/W # process creation
WinExec # command execution
IsDebuggerPresent # anti-debug check
CreateRemoteThread # code injection
Anti-anti-debug plugins:
- ScyllaHide
- SharpOD
- TitanHide
GDB (Linux):
gdb ./sample
set disassembly-flavor intel
break main
run
info registers
x/20i $rip # disassemble 20 instructions
x/10x $rsp # examine stack
# GEF (GDB Enhanced Features)
# Better UI, heap analysis, pattern generation
SANDBOX ANALYSIS#
Online sandboxes:
ANY.RUN:
- Interactive sandbox (control execution)
- Real-time process tree, network, file changes
- Free tier: public submissions, Windows 7/10
- URL: https://any.run
Joe Sandbox:
- Deep behavioral analysis
- Multiple OS support
- Detailed reports with MITRE ATT&CK mapping
- URL: https://www.joesandbox.com
Hybrid Analysis (CrowdStrike):
- Free community edition
- VxStream Sandbox backend
- URL: https://www.hybrid-analysis.com
VirusTotal:
- Multi-AV scanning (70+ engines)
- Behavioral analysis (sandboxes)
- URL: https://www.virustotal.com
Triage (Hatching):
- Fast automated analysis
- URL: https://tria.ge
CAPE Sandbox (self-hosted):
- Fork of Cuckoo Sandbox
- Config extraction for many malware families
- URL: https://github.com/kevoreilly/CAPEv2
Local sandbox:
Cuckoo Sandbox / CAPE:
- Self-hosted automated analysis
- Requires: host (Linux), guest VMs (Windows)
- Reports: API calls, network, dropped files, screenshots
YARA RULES#
Basic syntax:
rule MalwareExample {
meta:
author = "Analyst"
description = "Detects Example Malware"
date = "2026-03-19"
hash = "abc123..."
strings:
$s1 = "malicious_string" ascii wide
$s2 = { 4D 5A 90 00 } // hex pattern (MZ header)
$s3 = /https?:\/\/[a-z0-9\.\-]+/ // regex
$s4 = "cmd.exe /c" nocase
$pdb = "C:\\Users\\attacker\\malware.pdb"
condition:
uint16(0) == 0x5A4D and // PE file
filesize < 5MB and
(2 of ($s*) or $pdb)
}
Running YARA:
yara rules.yar sample.exe # scan single file
yara -r rules.yar /path/to/directory/ # recursive scan
yara -s rules.yar sample.exe # show matching strings
yara -c rules.yar /path/ # count matches
yara -t malware rules.yar /path/ # filter by tag
Useful YARA modules:
import "pe"
import "math"
import "hash"
rule HighEntropy {
condition:
math.entropy(0, filesize) > 7.5
}
rule SuspiciousImports {
condition:
pe.imports("kernel32.dll", "VirtualAllocEx") and
pe.imports("kernel32.dll", "WriteProcessMemory") and
pe.imports("kernel32.dll", "CreateRemoteThread")
}
YARA rule sources:
- https://github.com/Yara-Rules/rules
- https://github.com/Neo23x0/signature-base
- https://github.com/InQuest/awesome-yara
BEHAVIORAL INDICATORS (IOCS)#
File system: - Files created in %TEMP%, %APPDATA%, %PROGRAMDATA% - Executables in non-standard locations - Files with double extensions (report.pdf.exe) - Hidden files and directories - Modified system files Registry: - Run/RunOnce keys modified - New services created - Image File Execution Options (debugger persistence) - Firewall rules disabled - Security center notifications disabled Network: - DNS queries to suspicious domains - HTTP POST with encoded data - Connections to known C2 infrastructure - Beaconing behavior (regular intervals) - Large data exfiltration - TOR or proxy usage Process: - Injection into legitimate processes - Process hollowing - Unusual parent-child relationships - Privilege escalation attempts
ANALYSIS REPORT TEMPLATE#
1. EXECUTIVE SUMMARY - Malware type/family - Severity assessment - Key findings 2. SAMPLE INFORMATION - Filename, size, type - MD5, SHA1, SHA256 hashes - SSDeep fuzzy hash - First seen / submission date 3. STATIC ANALYSIS - File type and packer info - Notable strings - Imports/exports of interest - Compilation timestamp - Digital signatures 4. DYNAMIC ANALYSIS - Execution behavior - File system changes - Registry modifications - Network communications - Process activity 5. INDICATORS OF COMPROMISE - File hashes - File paths created/modified - Registry keys - Network indicators (IPs, domains, URLs) - Mutexes - YARA signatures 6. MITRE ATT&CK MAPPING - Tactics and techniques observed 7. RECOMMENDATIONS - Detection signatures - Mitigation steps - Remediation actions
REFERENCES#
- Practical Malware Analysis (Sikorski & Honig) - FlareVM: https://github.com/mandiant/flare-vm - REMnux: https://remnux.org/ - YARA: https://virustotal.github.io/yara/ - MITRE ATT&CK: https://attack.mitre.org/