โ† All cheat sheets

MALWARE-ANALYSIS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Practical guide to setting up a malware analysis lab and performing
static and dynamic analysis safely.

SAFE LAB SETUP#

Option 1: FlareVM (Windows Analysis)
  Requirements: Windows 10/11 VM, 4GB+ RAM, 60GB+ disk
  Install:
    1. Fresh Windows VM (disable Windows Update)
    2. Snapshot clean state
    3. Open PowerShell as Admin:
       Set-ExecutionPolicy Unrestricted -Force
       (New-Object net.webclient).DownloadFile(
         'https://raw.githubusercontent.com/mandiant/flare-vm/main/install.ps1',
         "$env:USERPROFILE\Desktop\install.ps1")
       Unblock-File "$env:USERPROFILE\Desktop\install.ps1"
       & "$env:USERPROFILE\Desktop\install.ps1"
    4. Wait for installation (1-2 hours)
    5. Snapshot "FlareVM-Ready"
  Includes: x64dbg, PEStudio, Ghidra, IDA Free, Process Monitor,
            Wireshark, Python, YARA, and 200+ tools

Option 2: REMnux (Linux Analysis)
  Requirements: Ubuntu-based VM, 4GB+ RAM, 60GB+ disk
  Install:
    wget https://REMnux.org/remnux-cli
    chmod +x remnux-cli
    sudo mv remnux-cli /usr/local/bin/remnux
    sudo remnux install --mode=full
  Includes: radare2, Ghidra, YARA, ClamAV, oledump, oletools,
            pdfparser, peframe, binwalk, Wireshark, inetsim

Network Isolation:
  - Use Host-Only or Internal network in VMware/VirtualBox
  - INetSim on REMnux to simulate internet services
  - FakeDNS for DNS simulation
  - Configure: sudo inetsim --config /etc/inetsim/inetsim.conf
  - Never analyze malware on host or production network

Snapshot Strategy:
  1. Clean OS install
  2. Tools installed (FlareVM/REMnux ready)
  3. Pre-analysis (revert here before each sample)

STATIC ANALYSIS - INITIAL TRIAGE#

File identification:
  file sample.exe                        # file type identification
  file sample.dll
  exiftool sample.exe                    # metadata extraction

Hashing:
  md5sum sample.exe
  sha256sum sample.exe
  ssdeep sample.exe                      # fuzzy hash for similarity

  # Check hash on VirusTotal
  curl -s "https://www.virustotal.com/api/v3/files/<SHA256>" \
    -H "x-apikey: <YOUR_API_KEY>"

Strings extraction:
  strings sample.exe                     # ASCII strings
  strings -el sample.exe                 # Unicode (little-endian)
  strings sample.exe | grep -i "http\|https\|ftp\|www"    # URLs
  strings sample.exe | grep -iE "\b[A-Za-z0-9._%+-]+@"    # emails
  strings sample.exe | grep -iE "([0-9]{1,3}\.){3}[0-9]"  # IPs
  strings sample.exe | grep -i "password\|key\|token\|secret"
  strings sample.exe | grep -i "cmd\|powershell\|wscript"

  # FLOSS (FLARE Obfuscated String Solver) - finds encoded strings
  floss sample.exe
  floss --no-static-strings sample.exe   # only decoded strings

PE Analysis (Windows executables):
  PEStudio:
    - GUI tool on FlareVM
    - Shows imports, sections, resources, signatures
    - Highlights suspicious indicators
    - Checks against VirusTotal

  pestudio (CLI):
    pestudio sample.exe

  pefile (Python):
    import pefile
    pe = pefile.PE('sample.exe')
    print(pe.FILE_HEADER.TimeDateStamp)       # compilation timestamp
    for section in pe.sections:
        print(section.Name, hex(section.VirtualAddress),
              section.SizeOfRawData, section.get_entropy())
    for entry in pe.DIRECTORY_ENTRY_IMPORT:
        print(entry.dll)
        for imp in entry.imports:
            print(f"  {imp.name}")

  Detect It Easy (DIE):
    - Identifies packers, compilers, protectors
    - Shows entropy graph (high entropy = packed/encrypted)
    - Detects UPX, Themida, VMProtect, custom packers

  CFF Explorer:
    - PE header viewer and editor
    - Import/export table analysis
    - Resource viewer

Packer detection and unpacking:
  # Entropy check (>7.0 suggests packing)
  python3 -c "
  import pefile, math
  pe = pefile.PE('sample.exe')
  for s in pe.sections:
      print(f'{s.Name.decode().strip(chr(0)):8s} entropy: {s.get_entropy():.2f}')
  "

  # UPX unpacking
  upx -d sample.exe -o sample_unpacked.exe

  # For custom packers: dynamic unpacking with x64dbg
  # Set breakpoint on VirtualAlloc/VirtualProtect, dump unpacked PE

Document analysis:
  # Office documents
  olevba sample.docm                     # extract VBA macros
  oledump.py sample.doc                  # OLE stream analysis
  oledump.py -s <stream_num> -v sample.doc  # dump specific stream

  # PDF analysis
  pdfparser.py sample.pdf
  pdfparser.py --search javascript sample.pdf
  pdf-parser.py -f sample.pdf            # filter suspicious
  peepdf -f sample.pdf                   # interactive analysis

STATIC ANALYSIS - DEEPER DIVE#

Disassembly / Decompilation:
  Ghidra (free, NSA):
    - Import binary, auto-analyze
    - CodeBrowser for disassembly + decompilation
    - Function graph view for control flow
    - Cross-references (Ctrl+Shift+F)
    - Script manager for automation

  IDA Free:
    - Industry standard disassembler
    - Free version: x86/x64 cloud decompiler
    - Graph view, proximity view
    - Rename functions and variables for clarity

  radare2 / Cutter:
    r2 -A sample.exe                     # analyze all
    afl                                  # list functions
    s main; pdf                          # seek to main, print disassembly
    VV                                   # visual graph mode

  Binary Ninja (commercial):
    - Modern UI, HLIL/MLIL/LLIL
    - Good API for scripting

DYNAMIC ANALYSIS - BEHAVIORAL#

Process Monitor (ProcMon):
  - Filter by process name: sample.exe
  - Capture: file system, registry, network, process activity
  - Key filters:
    Operation is WriteFile
    Operation is RegSetValue
    Operation is TCP Connect
    Operation is Process Create
  - Save as CSV/PML for analysis

Process Explorer:
  - Real-time process tree
  - DLL list per process
  - Handle viewer
  - VirusTotal integration
  - Verify image signatures

API Monitor:
  - Hook and log API calls
  - Filter by category (file, registry, network, crypto)
  - Useful for understanding malware behavior

Wireshark / tshark:
  # Capture during execution
  wireshark -i eth0 -k -w capture.pcap

  # Filter C2 traffic
  tshark -r capture.pcap -Y "dns" -T fields -e dns.qry.name
  tshark -r capture.pcap -Y "http.request" -T fields -e http.host -e http.request.uri
  tshark -r capture.pcap -Y "tls.handshake.extensions_server_name" \
    -T fields -e tls.handshake.extensions_server_name

Regshot:
  - Take snapshot before execution (1st shot)
  - Run malware
  - Take snapshot after (2nd shot)
  - Compare: shows registry and file changes

DYNAMIC ANALYSIS - DEBUGGING#

x64dbg (Windows):
  Key shortcuts:
    F2  - Set breakpoint
    F7  - Step into
    F8  - Step over
    F9  - Run
    Ctrl+G - Go to address/expression

  Common breakpoints for malware:
    CreateFileA/W              # file operations
    WriteFile                  # file writes
    RegSetValueExA/W           # registry modifications
    InternetOpenA/W            # network initialization
    HttpSendRequestA/W         # HTTP requests
    WSAStartup                 # Winsock init
    connect                    # network connections
    VirtualAlloc               # memory allocation (unpacking)
    VirtualProtect             # memory permission change
    CreateProcessA/W           # process creation
    WinExec                    # command execution
    IsDebuggerPresent          # anti-debug check
    CreateRemoteThread         # code injection

  Anti-anti-debug plugins:
    - ScyllaHide
    - SharpOD
    - TitanHide

GDB (Linux):
  gdb ./sample
  set disassembly-flavor intel
  break main
  run
  info registers
  x/20i $rip                  # disassemble 20 instructions
  x/10x $rsp                  # examine stack

  # GEF (GDB Enhanced Features)
  # Better UI, heap analysis, pattern generation

SANDBOX ANALYSIS#

Online sandboxes:
  ANY.RUN:
    - Interactive sandbox (control execution)
    - Real-time process tree, network, file changes
    - Free tier: public submissions, Windows 7/10
    - URL: https://any.run

  Joe Sandbox:
    - Deep behavioral analysis
    - Multiple OS support
    - Detailed reports with MITRE ATT&CK mapping
    - URL: https://www.joesandbox.com

  Hybrid Analysis (CrowdStrike):
    - Free community edition
    - VxStream Sandbox backend
    - URL: https://www.hybrid-analysis.com

  VirusTotal:
    - Multi-AV scanning (70+ engines)
    - Behavioral analysis (sandboxes)
    - URL: https://www.virustotal.com

  Triage (Hatching):
    - Fast automated analysis
    - URL: https://tria.ge

  CAPE Sandbox (self-hosted):
    - Fork of Cuckoo Sandbox
    - Config extraction for many malware families
    - URL: https://github.com/kevoreilly/CAPEv2

Local sandbox:
  Cuckoo Sandbox / CAPE:
    - Self-hosted automated analysis
    - Requires: host (Linux), guest VMs (Windows)
    - Reports: API calls, network, dropped files, screenshots

YARA RULES#

Basic syntax:
  rule MalwareExample {
      meta:
          author = "Analyst"
          description = "Detects Example Malware"
          date = "2026-03-19"
          hash = "abc123..."

      strings:
          $s1 = "malicious_string" ascii wide
          $s2 = { 4D 5A 90 00 }              // hex pattern (MZ header)
          $s3 = /https?:\/\/[a-z0-9\.\-]+/   // regex
          $s4 = "cmd.exe /c" nocase
          $pdb = "C:\\Users\\attacker\\malware.pdb"

      condition:
          uint16(0) == 0x5A4D and            // PE file
          filesize < 5MB and
          (2 of ($s*) or $pdb)
  }

Running YARA:
  yara rules.yar sample.exe               # scan single file
  yara -r rules.yar /path/to/directory/    # recursive scan
  yara -s rules.yar sample.exe            # show matching strings
  yara -c rules.yar /path/                 # count matches
  yara -t malware rules.yar /path/         # filter by tag

Useful YARA modules:
  import "pe"
  import "math"
  import "hash"

  rule HighEntropy {
      condition:
          math.entropy(0, filesize) > 7.5
  }

  rule SuspiciousImports {
      condition:
          pe.imports("kernel32.dll", "VirtualAllocEx") and
          pe.imports("kernel32.dll", "WriteProcessMemory") and
          pe.imports("kernel32.dll", "CreateRemoteThread")
  }

YARA rule sources:
  - https://github.com/Yara-Rules/rules
  - https://github.com/Neo23x0/signature-base
  - https://github.com/InQuest/awesome-yara

BEHAVIORAL INDICATORS (IOCS)#

File system:
  - Files created in %TEMP%, %APPDATA%, %PROGRAMDATA%
  - Executables in non-standard locations
  - Files with double extensions (report.pdf.exe)
  - Hidden files and directories
  - Modified system files

Registry:
  - Run/RunOnce keys modified
  - New services created
  - Image File Execution Options (debugger persistence)
  - Firewall rules disabled
  - Security center notifications disabled

Network:
  - DNS queries to suspicious domains
  - HTTP POST with encoded data
  - Connections to known C2 infrastructure
  - Beaconing behavior (regular intervals)
  - Large data exfiltration
  - TOR or proxy usage

Process:
  - Injection into legitimate processes
  - Process hollowing
  - Unusual parent-child relationships
  - Privilege escalation attempts

ANALYSIS REPORT TEMPLATE#

1. EXECUTIVE SUMMARY
   - Malware type/family
   - Severity assessment
   - Key findings

2. SAMPLE INFORMATION
   - Filename, size, type
   - MD5, SHA1, SHA256 hashes
   - SSDeep fuzzy hash
   - First seen / submission date

3. STATIC ANALYSIS
   - File type and packer info
   - Notable strings
   - Imports/exports of interest
   - Compilation timestamp
   - Digital signatures

4. DYNAMIC ANALYSIS
   - Execution behavior
   - File system changes
   - Registry modifications
   - Network communications
   - Process activity

5. INDICATORS OF COMPROMISE
   - File hashes
   - File paths created/modified
   - Registry keys
   - Network indicators (IPs, domains, URLs)
   - Mutexes
   - YARA signatures

6. MITRE ATT&CK MAPPING
   - Tactics and techniques observed

7. RECOMMENDATIONS
   - Detection signatures
   - Mitigation steps
   - Remediation actions

REFERENCES#

- Practical Malware Analysis (Sikorski & Honig)
- FlareVM: https://github.com/mandiant/flare-vm
- REMnux: https://remnux.org/
- YARA: https://virustotal.github.io/yara/
- MITRE ATT&CK: https://attack.mitre.org/