DIY Malware Analysis Lab for Free (with CrackMe Challenge!) | master0Fnone Ep. 2.1: Sandbox in a Box

  Рет қаралды 1,229

jeFF0Falltrades

jeFF0Falltrades

Күн бұрын

(Part 1 of 2)
If you've ever wanted to analyze malware on your own without spending a fortune, this is your time.
In this free master0Fnone class, you will learn to:
1. Build a simple malware analysis lab for FREE, using 2 virtual machines (Remnux and Windows 10) and several free analysis and monitoring tools
2. Snapshot your lab and make it exportable so you can bring it anywhere
3. Examine some real malware samples in your newly-built sandbox, test out the tools we installed, and discover how to pull indicators of compromise and artifacts for detections and determining what the malware is trying to accomplish
4. Challenge you to take what you've learned and use it to achieve an entry on the "Wall of Fame" by analyzing the included "CrackMe" program and finding all the flags!
The jeFF0Falltrades master0Fnone Class series is a collection of free online courses dedicated to making learning complex topics - like malware analysis - more accessible (and fun) to everyone.
Please leave feedback and questions here as comments, or DM me on Mastodon (social links listed on the channel).
Check the pinned comment for any updates to the content.
Let me know what you would like to see in future videos!
Project Homepage and CrackMe Challenge Instructions: github.com/jeFF0Falltrades/Tu...
CrackMe Challenge Form: forms.gle/nE2yFZowxhCKBPw37
Thank you to these incredible artists whose works were featured in this video:
Thumbnail image derived from this work by gstudioimagen1 on Freepik
www.freepik.com/free-vector/v...
Intro Music from #Uppbeat (free for Creators!):
uppbeat.io/t/monument-music/m...
License code: ZD860DLJBOAVDIIH
Intro Music from #Uppbeat (free for Creators!):
uppbeat.io/t/soundroll/transcend
License code: YMTA0L5AOB19X1SV
00:00:00 - Sarcastic Intro & Unsarcastic Apology
00:02:57 - Course Overview
00:05:35 - Important Notes
00:07:57 - Part 1 Start/VirtualBox install
00:11:55 - Importing/Configuring Remnux
00:15:29 - Detour: FLARE-VM
00:16:55 - Remnux VM settings
00:20:35 - VirtualBox Guest Additions (Remnux)
00:21:57 - Accessing shared folders (Remnux)
00:22:58 - Upgrading/Updating Remnux
00:23:47 - Detour: Validating our network connection
00:25:54 - Custom tools/parse_hashes.sh
00:32:35 - the RAT King Parser
00:33:37 - INetSim configuration
00:38:36 - Creating our virtual network
00:46:29 - Burpsuite/INetSim troubleshooting & setup
00:52:12 - Finishing our Remnux machine
00:53:32 - our Windows VM/troubleshooting
01:02:00 - Disabling Windows Update
01:04:00 - pafish (Paranoid Fish) & VBoxCloak
01:11:48 - Disabling Windows Defender & Firewall
01:16:46 - Networking setup (Windows)
01:18:17 - Testing HTTPS traffic capture w/ the Burpsuite root certificate
01:23:43 - Creating the final Clean snapshot for Remnux
01:25:33 - Ghidra/JDK/Python/7Zip & Revealing hidden files/folders/extensions
01:31:43 - IDA Free
01:32:45 - x64dbg
01:34:06 - System Informer/Process Hacker
01:35:25 - Process Monitor
01:36:41 - Chrome
01:37:08 - Wireshark
01:39:57 - LibreOffice/Setting macro security
01:44:07 - .NET 8.0 SDK
01:44:30 - dnSpy
01:46:05 - Capture-Py
01:48:27 - Detect-It-Easy
01:50:05 - de4dot
01:52:21 - pe-sieve
01:54:10 - VbsEdit
01:55:11 - CMD Watcher
01:57:23 - ProcessSpawnControl
02:00:30 - Exporting VMs/Last-minute crises/troubleshooting
02:07:31 - Disabling Edge running in background
02:08:50 - Cleanup and final snapshots
02:10:20 - False ending/fixing procmon
02:11:28 - Congratulations! End of Episode 2.1

Пікірлер: 16
@jeFF0Falltrades
@jeFF0Falltrades 25 күн бұрын
To my loyal and wonderful subs: I apologize again for the delay on this one - our 10,000 sub celebration is now an 11,000 sub celebration, which is awesome, but I am sorry it took this long to push this out and I hope the wait was worth it ❤️ Check this pinned comment for corrections and updates and thanks for watching! EDIT: Thanks to @BrakeSec for the suggestion, I added a simple helper script so you don't have to worry about commenting out the netplan configuration yourself; It's added to the repo!
@CrusaderMen
@CrusaderMen 24 күн бұрын
Thank you I love your content
@jeFF0Falltrades
@jeFF0Falltrades 24 күн бұрын
@@CrusaderMen Thank *you*! I hope you enjoy this one too
@lukefidalgo8154
@lukefidalgo8154 25 күн бұрын
Just as I bought Practical Malware Analysis (the alien book), this video comes out! Some really good timing! :P
@jeFF0Falltrades
@jeFF0Falltrades 25 күн бұрын
YES!!! I'm so happy for you because that book is a treat. And you'll find my set up is very akin to the one in the book, so I hope this complements it well :-). Also, if you're interested, No Starch Press just this month came out with another book called "Evasive Malware" that I call out in this video. I haven't read through all of it yet, but what I have read has been really good! Thanks for watching and I hope you enjoy both this and PMA!
@Jarvx
@Jarvx 12 күн бұрын
The alien book is top tier :)
@0ri0nexe
@0ri0nexe 24 күн бұрын
The king posted ! Stop what ur doing and open your best disassembler ;) Jokes aside i like how you introduction more and more useful tools each video
@jeFF0Falltrades
@jeFF0Falltrades 24 күн бұрын
@@0ri0nexe Man you made my day hahaha. I’m in the middle of finishing up editing Part 2 (which I can say DEFINITIVELY will be out tomorrow AM, Eastern Time), and I really needed this motivation. Thanks for being a great hype man and I am glad you find the tools useful! I’m so happy to finally share my lab setup as it’s been good to me all these years.
@0ri0nexe
@0ri0nexe 24 күн бұрын
​@@jeFF0Falltrades Two videos in a row, what a time to be alive.
@jeFF0Falltrades
@jeFF0Falltrades 24 күн бұрын
@@0ri0nexe 🤣
@micha7863
@micha7863 25 күн бұрын
Great job! Appreciate it veeery much. Also congrats on becoming a dad. BTW: I have tested VBox 7 Unattended installation for Win10 and I always had problems with the VM - freezes/slow running (problem is confirmed by other users having the same issue).
@jeFF0Falltrades
@jeFF0Falltrades 25 күн бұрын
Thanks so much on both accounts, and thanks for being here!
@jeFF0Falltrades
@jeFF0Falltrades 25 күн бұрын
@@micha7863 thanks for attesting to the unattended installation stuff as well - as you’ll see (if you haven’t already) it DOES cause issues for me as well 🥴
@micha7863
@micha7863 25 күн бұрын
@@jeFF0Falltradesoh ok, i was commenting while watching, thanks again!
@jeFF0Falltrades
@jeFF0Falltrades 24 күн бұрын
I figured haha. Didn't mean to spoil it for you, but yeah, had quite a few "live" troubleshooting instances with VirtualBox/Windows
CrowdStrike IT Outage Explained by a Windows Developer
13:40
Dave's Garage
Рет қаралды 2,1 МЛН
ЧУТЬ НЕ УТОНУЛ #shorts
00:27
Паша Осадчий
Рет қаралды 10 МЛН
Spot The Fake Animal For $10,000
00:40
MrBeast
Рет қаралды 187 МЛН
Double Stacked Pizza @Lionfield @ChefRush
00:33
albert_cancook
Рет қаралды 111 МЛН
One Script Tag Just Pwn'd Over 100,000 Websites
16:04
Theo - t3․gg
Рет қаралды 131 М.
How to Crack Software (Reverse Engineering)
16:16
Eric Parker
Рет қаралды 188 М.
Which Linux distribution and GUI to choose ?
27:34
benlinux-en
Рет қаралды 4,7 М.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,4 МЛН
Hacking Windows TrustedInstaller (GOD MODE)
31:07
John Hammond
Рет қаралды 427 М.
Why Isn't Functional Programming the Norm? - Richard Feldman
46:09
I Bought a $5000 PC in a Random Asian Tech Mall
22:12
Linus Tech Tips
Рет қаралды 6 МЛН
🔴 Malware Mondays Episode 01 - Identifying Malicious Activity in Process Monitor (ProcMon) Data
55:51
Xiaomi SU-7 Max 2024 - Самый быстрый мобильник
32:11
Клубный сервис
Рет қаралды 537 М.
iPhone socket cleaning #Fixit
0:30
Tamar DB (mt)
Рет қаралды 18 МЛН
İĞNE İLE TELEFON TEMİZLEMEK!🤯
0:17
Safak Novruz
Рет қаралды 1,6 МЛН
КРУТОЙ ТЕЛЕФОН
0:16
KINO KAIF
Рет қаралды 6 МЛН
$1 vs $100,000 Slow Motion Camera!
0:44
Hafu Go
Рет қаралды 28 МЛН