(Part 2 of 2)
If you've ever wanted to analyze malware on your own without spending a fortune, this is your time.
In this free master0Fnone class, you will learn to:
1. Build a simple malware analysis lab for FREE, using 2 virtual machines (Remnux and Windows 10) and several free analysis and monitoring tools
2. Snapshot your lab and make it exportable so you can bring it anywhere
3. Examine some real malware samples in your newly-built sandbox, test out the tools we installed, and discover how to pull indicators of compromise and artifacts for detections and determining what the malware is trying to accomplish
4. Challenge you to take what you've learned and use it to achieve an entry on the "Wall of Fame" by analyzing the included "CrackMe" program and finding all the flags!
The jeFF0Falltrades master0Fnone Class series is a collection of free online courses dedicated to making learning complex topics - like malware analysis - more accessible (and fun) to everyone.
Please leave feedback and questions here as comments, or DM me on Mastodon (social links listed on the channel).
Check the pinned comment for any updates to the content.
Let me know what you would like to see in future videos!
Project Homepage and CrackMe Challenge Instructions: https://github.com/jeFF0Falltrades/Tu...
CrackMe Challenge Form: https://forms.gle/nE2yFZowxhCKBPw37
Thank you to these incredible artists whose works were featured in this video:
Thumbnail image derived from this work by gstudioimagen1 on Freepik
https://www.freepik.com/free-vector/v...
00:00:00 - Intro to Part 2
00:02:59 - Start XWorm analysis
00:05:24 - Analysis workflow/checking the script
00:08:31 - Setting up monitoring tools
00:13:58 - Running the XWorm sample
00:15:51 - Examining dropped scripts
00:16:45 - Watching the malware run in memory
00:19:33 - Extracting the payload using pe-sieve
00:21:02 - Using procmon to find the keylogger log
00:22:47 - Decompiling and extracting the configuration in dnSpy
00:25:19 - Modifying INetSim to analyze C2 communication
00:29:45 - Examining strings in memory using System Informer
00:36:07 - Wrapping up XWorm; Start examining macros from maldoc
00:39:20 - Macro analysis w/ OLE tools and ViperMonkey on Remnux
00:41:29 - Extracting an embedded EXE w/ ViperMonkey
00:42:34 - Examining the payload with Detect-It-Easy
00:43:09 - Analyzing the loader program
00:48:11 - Examining the loaded malware
00:52:27 - Analyzing network traffic from the malware
00:57:57 - Dumping the payload w/ pe-sieve and analyzing w/ dnSpy
00:59:08 - Using RAT King Parser to dump the RAT config
01:02:36 - End AsyncRAT; Start Adwind
01:07:16 - Examining the files dropped by Adwind
01:11:12 - Using jd-gui and Bytecode-Viewer to decompile JARs
01:15:48 - Quick look at jadx
01:16:30 - Improv Python decoding!
01:17:03 - Dumping Java classes using Bytecode-Viewer
01:18:02 - End Adwind; Start Royal Ransomware
01:19:57 - Debugging the ransomware w/ x64dbg/x32dbg
01:23:04 - Examining command-line flags for Royal
01:25:21 - Reverse engineering the -id flag
01:27:45 - Ransomware'ing ourselves (safely)
01:28:58 - Examining the ransomware's enumeration traffic
01:32:25 - Wrapping up Royal Ransomware
01:32:56 - Your turn! Go forth and do the CrackMe challenge!