Hey everyone, I messed up the editing for this release and two clips are out of order. The correct order for Parts I and II of Dynamic Analysis of an Unknown Binary should be as follows: 3:00:54 - Part 1 Basic Dynamic Analysis 2:39:37 - Part 2 Basic Dynamic Analysis I apologize for the confusion!
@zizzixsec Жыл бұрын
A side note for anyone who runs wannacry at the first detonation and nothing happens, Make sure you disable inetsim on the remnux box as the first thing wannacry does is reach out for a dns host and if it replies, it wont run. Thats how Marcus disabled it in the first place.
@PlentyRude Жыл бұрын
Thanks!
@0xKilty Жыл бұрын
Thank you for this
@ily_alex1 Жыл бұрын
thank you so much, I've actually been stuck on this for some time, and it was like the first time in my life I was frustrated over a piece of malware that doesn't wanna run on my system
@repairstudio494010 ай бұрын
Very helpful, thank you ❤
@KenPryor Жыл бұрын
I recently completed the full 9 hour course on TCM and loved it. Great class!
@wiredogsec2 жыл бұрын
Thank you! I managed to pick up the full course (as well as others) during the $1-$6 discount event! You guys are awesome! I am halfway through PMAT and I am enjoying it. This is definitely worth the money! TCM Security has high quality and very affordable training.
@khodorj65812 жыл бұрын
Hello, i want to ask how can I drag and drop the malware folder from host to FlareVM, not able to perform this action
@wiredogsec2 жыл бұрын
@@khodorj6581 I am using VMware Workstation and I had to install VMware tools. There is probably a similar process for VMware Player or VirtualBox.
@talalsallmart1 Жыл бұрын
@@khodorj6581 in vm settings set them drag modes to bi directional
@d4ddyn0n4me82 жыл бұрын
Im about 60% through your course loving it gotta stalk your youtube for everything i need more.. MOOORE 👁️👄👁️ Would definetly recommend his course for anyone reading :D
@somberrage46922 жыл бұрын
Excellent resource. Certainly appreciate the effort that went into this! I encountered an issue with the Windows machine where it wouldn't be fed any fake html page after manually setting the DNS on the Windows machine for the Remnux host. The issue was with the LAN Settings Automatically Detect Settings configuration. Unchecking this box within Internet Explorer resolved the matter. Just in case anyone oberves this as well.
@tannerjones13312 жыл бұрын
Great course! I just made it through the tutorial! I was able to solidify my understanding on basic malware analysis. I have taken a course in my graduate studies and it was a great supplement.
@ReMaX2013 Жыл бұрын
i just completed the course , i really want to thank you for sharing that for free
@carenmorenmoren9156 Жыл бұрын
I don't usually comment on KZbin but you deserve admirations. I will make sure to mention you in every interview I have for Threat Intel position and to everyone who is interested in Threat Intel/Malware analysis career path. Thank you is not enough.
@huskyhacks2 жыл бұрын
Hey fam! I just released a new, free section of PMAT that includes more detail about the security of Host Only networks and how to set up an Internal Network for malware analysis. It fits right in after the video at 51:39:00. Check it out here: notes.huskyhacks.dev/blog/malware-analysis-labs-internal-network-vs-host-only
@hywellbutrotmg4 ай бұрын
damn i knew you made long courses but 51 hours is insane
@francesco2092 Жыл бұрын
this is why they say that teaching is an art... you can make someone who knows nothing understand things and slowly take them to the next level is spectacular... as soon as I finish these 5 hours I can't wait to go to buy the rest of the course.
@repairstudio494010 ай бұрын
This has been such an amazing journey. Much respect to Husky! Heath's crew @ TCM are awesome! 🎉
@spammers7431Ай бұрын
Just completed this course its soooo awsome
@filippogiorgiorondo69325 күн бұрын
sorry but u desable windows updates and windows defender?
@daredevil_orchid2 жыл бұрын
Man you are so generous. Now I can tell my Junior to learn from here to know if he's into malware analysis. Btw I already have the full course and I'm halfway done.
@Manjith233 ай бұрын
@daredevil_orchid hieee
@MehwishAli-w9i11 ай бұрын
In remnux when i mount it said no medium found on dev/sro what i can do for these
@gameblendingreality5 ай бұрын
Go to devices>insert guest additions cd image... >run
@skullhead838123 күн бұрын
@@gameblendingreality thanks i have been struggling with this for 3 days now i don't really know how to use linux so i am using virtualbox but whenever i install a live cd or ova no medium found occurs
@logicbypass2 жыл бұрын
Some may have noticed that the part of Basic Dynamic Analysis was not mounted in the proper order. 3:00:54 - Part 1 Basic Dynamic Analysis 2:39:37 - Part 2 Basic Dynamic Analysis Thank you @huskyhacks531 for a fantastic tutorial
@huskyhacks2 жыл бұрын
Yep, I just realized this. Thank you for pointing it out. I just looked into the editor to see if I could rearrange the order but it doesn't look like that's the case. I'll add something to the description and a pinned comment to try to clear up any confusion.
@meyvesuyudunyasi11 күн бұрын
really realley excellent course, thank you
@scottcarey24832 жыл бұрын
Glad I found this video. I'm getting in to malware analysis in my job and I think your course will be a great intro. Do you cover analysis of malicious websites too?
@atikullah906611 ай бұрын
best malware analysis course. Thanks for this amazing course
@firosiam77862 жыл бұрын
Good to see you share this much for free to many people God bless you.
@niless5775 ай бұрын
It was an amazing and helpful tutorial for beginner malware analiyst. Thank you so much, I was searching something like this and your content is exactly what I was looking on the internet. Thank you again🤗
@brandonevans51232 жыл бұрын
I can't wait to watch this all the way through! Thank you!
@rojjst Жыл бұрын
You earned a sub, my friend 😊
@mohsinhafeez2 жыл бұрын
I already have your course, but its good to see it on youtube :)
@NickGalaftion Жыл бұрын
Excellent intro to malware analysis ! great job ! looking fwd at many more videos ..
@Hanacan7511 ай бұрын
Thank you my friend. Excelent tutorial :) I'm cheering for you to do more. hhaha
@D3ltaLabs3 ай бұрын
How am I only finding your channel now.. great tutor. I'll slowly watch all your videos now.
@julieuzii6350 Жыл бұрын
awesome video, thank you for all the information. I am a cybersecurity student and found this video invaluable.
@libusengmengwai32152 жыл бұрын
Thank you Matt, we truly appreciate the 🎁
@philosphize Жыл бұрын
Thank you so much for this amazing tutorial Please release next set of malware analysis video
@youaregod23822 жыл бұрын
Thank You for this. i actually finished your course,it was really awesome experience lots of good learning, Highly recommended your course. A very good teacher😍😇
@rasperss_51766 ай бұрын
One tip, personally I would go the extra step and by ensuring clipboard sharing is disabled when deploying malware. I don't think he mentioned that and did notice he had it enabled when copying hashes to virus[.]total just my two cents. But great video none the less!
@gameblendingreality5 ай бұрын
It looks like Flare VM already defaults to disabling the clipboard
@_Slaze2 жыл бұрын
Thank you for the awesome course
@Lwyte17 Жыл бұрын
Im curious, has the FLAREVM installation changed? I went through the process but simply get a folder named Tools instead of FLARE. Also it seems the packages that get installed are different than those seen the video, for example no peview. Is that just necause theyve changed their tool lost in the config file?
@rodrigopatino3382 Жыл бұрын
How to filter on Procmon: 2:27:00 3:28:42
@_clavita2 жыл бұрын
I bought this and im so happy i did
@todorokiyosukedesu2 жыл бұрын
Did you bought it on TCM Security?
@_clavita2 жыл бұрын
@@todorokiyosukedesu yeah!
@Manjith233 ай бұрын
hello
@Manjith233 ай бұрын
@_clavita hello'
@علاويالاسدي-ي3ض2 жыл бұрын
I can't thank you enough, Matt 🌸💝
@BustinJustin951 Жыл бұрын
21:56 I get error "no medium found on /dev/sr0" :(
@ricorobinson3954 Жыл бұрын
It means the needed files are already on your distro. Your good to go!
@isuamalinato18033 ай бұрын
Hello, I’m stuck at the remnux phase where I’m supposed to mount a media It’s keeps telling me “/decdrom” does not exist I look forward to your assistance, thank you
@JaspherSanchez-k5c2 ай бұрын
me too stuck with remnux
@nicksunny10011 ай бұрын
Subscribed!!
@Don018412 жыл бұрын
Appreciate the effort you put in this video. Amazing content. What i liked about the video is the way it has been explain which clear and to the point. Thanks husky.
@wendy_113 Жыл бұрын
I cannot thank you enough.
@dendell8860 Жыл бұрын
Great Video..Thank you
@nelsonnelson31 Жыл бұрын
Good Lecture man!
@yaseerkadam94962 жыл бұрын
You're the best bruh
@TheTntwilliams20 күн бұрын
Great video and was wondering if you have AV enabled when you run your samples on the VM or did you disable
@RozzClips Жыл бұрын
Thank you so much
@Manavetri2 жыл бұрын
Brilliant !!!
@GaryBales-q3n2 ай бұрын
The vbox files on the cdrom exist but on Remnux the files do not exist in cdrom anywhere. I have watched the video up the the sudo mount segment 3x but not sure what to try differently. Thanks
@hristinaivanova22383 ай бұрын
Hi, I have an issue with the inetsim. I have done everything correctly step by step but I only get the message about the fake mode when I navigate to the 10.0.0.3 remnux IP. When I try to run any other site I get 'this site can't be reached'. Can I have some help, please?
@arturcorreia66158 ай бұрын
Windows Defender is not letting me detonate de virus :(
@Fatima-u7r2w Жыл бұрын
Thank you so much for all your hard working ,but I do not know why the commands did not work for with me at the beginning?
@AaryadevVRBLX2 жыл бұрын
Hello , I am not able to drag the malware folder from the host to FlareVM, anyone please help
@mahetsiedahi6530 Жыл бұрын
were you able to solve the problem?
@AaryadevVRBLX Жыл бұрын
@@mahetsiedahi6530 ITS BEEN A YEAR
@kzkaa.8 ай бұрын
@@mahetsiedahi6530 Turn on host to guest in the drag-and-drop setting
@gameblendingreality5 ай бұрын
I had the same issue. I just downloaded it from Flare VM using wget without any issues. I had to set the network settings back to default before doing so. Make sure nothing malicious is actually on the machine if doing this method
@francesco2092 Жыл бұрын
at the 4.00.31 i don't understand how i find the metasploit module for use the reverse shell?
@Katokasu-w4h2 ай бұрын
can you tell me where should i download all tools for malware analysis I have Installed Flare VM but some tools are not compelety download
@NewbieValorantYT6 ай бұрын
is it ok to enable the clipboard share feature on flarevm ?
@Lead3RVideos2 жыл бұрын
Gonna need to make some time for this.
@sagartimalsina41209 ай бұрын
Just a quick question.. why does my Network setting is not working? I tried everything but the configuration is just not working in my case? Any solution?
@114thp76 ай бұрын
Hi, mr Husky. I have a little bit problem. As you showed at 59:09 to run wannacry then try it in my flare VM but wannacry.exe didn't run. I wonder why this happened(defender was off) Thanks in advance
@mattanderson20746 ай бұрын
You probably have the same issue as me - using a Windows 10 build which is no longer vulnerable to wannacry.
@114thp76 ай бұрын
@@mattanderson2074 i dont know why, but it worked. Wannacry works properly
@Old_SDC Жыл бұрын
Waiting for Remnux to install 20:58 I’ll be back whenever I remember to continue 24:40
@filippogiorgiorondo69325 күн бұрын
I have a questio, didn't u disable windows updates and windows defender? bcause im trying to do but when i disable MsMp mi VM explode
@043-namanvora210 ай бұрын
hey husky i tried to download the repo on my physical host but the defender and browser didn't let me download the repo as it was detection viruses into it can you help me with it please
@OldDirtyDragon10 ай бұрын
Same issue. Best I can find, the latest version of Win10 does not allow users to disable MsMpEng.exe. It is owned by the system. That's Microsoft's main AV scanner. Have not found a way around it yet.
@043-namanvora210 ай бұрын
@@OldDirtyDragon well bro it is a very simple issue what i did that i cloned the repo using git clone command and further it was downloaded on the pc but i made sure i dont open or unzip the repo, i further enabled the drag n drop from host to machine option temporarily for flarevm after dropping the repo into the flarevm i disabled the drag n drop option from v box and made sure that i have deleted the cloned repo from my physical machine and during all this process i didn't touched or twitch the windows defender should work for you as well
@MehwishAli-w9i11 ай бұрын
floss cmmand not working in my cmd said that it is not recognizeble how to solve this issue
@quasaaaar2 жыл бұрын
Edit: I found the answer to the below from your later explanation. However I did waste plenty of time trying to figure out myself. Here what took me further in the wrong direction is when I tried to open the malz file with 7zip and it did actually open it and presented a heirarchy of files and even 2 executables inside. So perhaps you need to rearrange the video so the safety part comes before any detonation. This is so others don't waste time like me (or worse, do something harmful) Thanks. Original post: Hi. At 57:08 you jumped to the next video and started working with the wanacry exe. However the file from the repository extracted in the previous video is ransomeware.wanacy.exe.malz So how did we jump from that to that?!?
@huskyhacks2 жыл бұрын
That question and more are addressed in the course FAQ, which is located on the course Discord (link in description). If you get stuck like that please check the Discord, it's likely another student has asked the question before and we can get you back on track
@quasaaaar2 жыл бұрын
@@huskyhacks I found another problem in the youtube video. The 2 video parts of basic dynamics with RAT.Unknown are in reverse order. The first video comes 2nd and the 2nd video comes 1st.
@huskyhacks2 жыл бұрын
@@quasaaaar Do you mind replying with the time stamps of what you think is out of order? I just skimmed that section and it all looks to be in order
@quasaaaar2 жыл бұрын
@@huskyhacks for Rat.unknown: Part 2 @ 2:39:35 Part 1 @ 3:00:55
@huskyhacks2 жыл бұрын
@@quasaaaar The samples in the sections you've timestamped are different samples. The course material includes multiple samples in the Basic Dynamic Analysis section. The times you've mentioned correspond to Part 2 from the first sample and Part 1 from the second sample
@vedantpathak4382Ай бұрын
For Vmware users: If anyone face problem after configuring Static DNS in Flarevm, and on visiting any url or ip you are not getting any output. Please follow below steps: - uncheck connect a host to virtual adapter in vmnet interface - disconnect & reconnect network adapter of remnux and flarevm. - then please do allow port 53, 80, 443, 21 on firewall as it might block incoming traffic. (or simply disable ufw). - Also, always turn on inetsim utlity as inetsim user only. if you will turn on inetsim from root user, dns will not work. dont know the reason
@ninjaspeedone Жыл бұрын
When I try to mount the cdrom I get this error message, mount: /media/cdrom: no medium found on /dev/sr0.
@amirahabubakar32779 ай бұрын
Go to devices>insert guest additions cd image... >run
@hyperxalloy439123 күн бұрын
It asks for password @@amirahabubakar3277
@stressless8405 Жыл бұрын
This is phucking fantastic. Very well explained
@coolheis74692 жыл бұрын
Congrats for ur great work and thanks for the content! I wanted to ask u if the host only adapter is safe because somewhere i read that this is not the case since the vm can communicate with the host.
@huskyhacks2 жыл бұрын
I actually just wrote a new section of PMAT about this specifically! notes.huskyhacks.dev/blog/malware-analysis-labs-internal-network-vs-host-only
@RINAMISHRA-j5h11 ай бұрын
Hello Sir, I am facing one issue, whenever I try to arm any binary, win10 defender or firewall removes it, Although all security options are turned off, Via Real Time Protection, Registry entry, group security policy etc. Still whenever any binary is converted to armed mode, windows automatically removes it. Kindly help what to do?
@nostalgiagore Жыл бұрын
cutter and PEview are missing on flarevm
@hemaraj8223 Жыл бұрын
While mounting th CD-ROM directory It says no media found under /dev/sr0
@angelaguirre9384 Жыл бұрын
Just click on Devices -> Insert Guest Additions CD image... The no media found error should be solved after this
@ThatBlueFalcon10 ай бұрын
@@angelaguirre9384 Thanks for saving me!
@MAHAABID-s9p9 ай бұрын
I am still a beginner, how to install the files to my flare vm and I have no connection to the internet ?
@muhammedbadawy15437 ай бұрын
You download it into your main machine then enable drag and drop (host to guest) and transfer the files into the Flare VM
@سعدسعدالدهيمي3 ай бұрын
@@muhammedbadawy1543 Will there be any risk to my device?
@jj691 Жыл бұрын
@105:10 did you adjust your DNS and just edit that portion out?
@jj691 Жыл бұрын
Never mind you cleared the air on this about 10 minutes later! :)
@khodorj65812 жыл бұрын
Hello , I am not able to drag the malware folder from the host to FlareVM, any idea?
@AaryadevVRBLX2 жыл бұрын
Hi ,I am facing same issue,Can you please share if you already resolved the problem.
@imvishal8352 Жыл бұрын
@@AaryadevVRBLX @khodorj6581 Same here, have you found the way ? do share the idea.
@tomaszskrzypczak3294 Жыл бұрын
Hello, you need to enable drag and drop in your VM. On running VM, on toolbar, go to devices -> Drag and Drop -> Host to Guest
@BorisJohnsonMayor2 жыл бұрын
Was hoping someone could answer a question regarding downloading file samples directly from an EDR dashboard. For example, 365 Defender from MS allows me to download a password protected zip file with the sample in question. However, as I am signed in with the company admin account used to access the EDR dashboard and subsequently have to download the sample to my work machine, how can this be done safely? Do I create a read only account for the dashboard access and sign in to that account in a lab environment and then download the sample? Do I just download the zipped sample on my work machine and send it elsewhere? I'm trying to limit as much possible risk from downloading a sample during an investigation and unfortunately Microsoft don't make this easier in the 365 defender dashboard.
@haneesha35489 ай бұрын
i cannot find the flare-vm github repo
@hasanbacha77962 жыл бұрын
Hello, I am trying to find a way to contact Matt Kiely to ask him about his training video i just purchased and i am not able to mount the file.
@huskyhacks2 жыл бұрын
Hello, please check the description of this video for some notes about that issue.
@hyphen6868 ай бұрын
Can you show the same lab setup using VMware Workstation Pro? I haven't been able to find a single video on this topic.
@gameblendingreality5 ай бұрын
that's paid for. You can either use VMWare player or VirtualBox for free.
@hyphen6865 ай бұрын
@@gameblendingreality yeah i can intall them in VMWare player, but still struggling in isolating them. it is not the same as VirtualBox.
@gameblendingreality5 ай бұрын
@@hyphen686 so you’re talking about the network settings in vmware? I’d honestly throw it into ChatGPT and that should get you to a fixed spot
@josephblack7408 Жыл бұрын
My laptop doesn't support virtualization what to do in this condition?
@Robalo450 Жыл бұрын
lolololol
@junaidsheraz8520 Жыл бұрын
I'm trying to download labs from the URL given in description but it says "Virus detected" and then stopped downloading. Please solve my query
@TheRealTopTV Жыл бұрын
download it on the vm and not your host, after its down disable nat again
@reiserkeiser Жыл бұрын
That first malware file from close to an hour in just will not execute.
@mayavik10342 жыл бұрын
man disabling the Defender is a real PIA, I tried everything. Being Denied access, even with Administrator access. Does anyone here have any ideas.😰
@angelaguirre9384 Жыл бұрын
I'm trying to get through the course but I'm not able to run the powershell script from flare-vm. I'm stuck trying to disable Windows Defender... Damn, I've even followed all the links provided under the github repository to do this but none seem to work. Hence I'm stuck here trying to run the powershell script ...
@angelaguirre9384 Жыл бұрын
Just for anyone that might face the same issue. I just went ahead and installed Windows 11 on my VM. I was finally able to disable windows defender with the help of John Hammond's yt video. Flare VM install script has successfully ran and I will be continuing the course later today.
@buzgie Жыл бұрын
listening to all the safety spiels as a linux user is funny. I have a habit of just leaving malware .exes lying around my pc because it can't do anything aha
@IamJohnKelly22 күн бұрын
Do this course teach you how to build your own
@gadadharnayak5648 Жыл бұрын
is malware analysis job generally full time job or are there part time jobs as well?
@sambhavjain692910 ай бұрын
5:02 5:03 5:05
@opmfa18502 жыл бұрын
i installed inetsim and configured it like you did but i dont get a page when i try to access any web site
@ytriskad38892 жыл бұрын
did you fix it?
@opmfa18502 жыл бұрын
@@ytriskad3889 yes but dont remember how
@Crixus0112 Жыл бұрын
@@ytriskad3889 Hey, I had the same issue you had and was able to get it to work. Let me know if you still have this issue and I can tell you how I got mine to work and that might help in oyur case.
@ytriskad3889 Жыл бұрын
@@Crixus0112 yeah that would be nice
@wokhead4 ай бұрын
WannaCry doesnt work((
@nishadbabu81302 жыл бұрын
this course related to TCM security pratical malware analysis
@PavithraRR-e9c10 ай бұрын
Thank you very much for this video, can I get your mail id so that can discuss which are related to this in details. Am a PhD student and faculty in an organization, my work on this is very interesting.
@Muhammad80008 Жыл бұрын
Cool :)
@emilisha-in4xl Жыл бұрын
Is this course basic or advanced?
@RINAMISHRA-j5h11 ай бұрын
hello
@piyushgayaki966711 ай бұрын
Thanks a lot sir. Just what to know for after ransomware detonation which tools I can use for dynamic analysis like you have shown how to use procmon and procexp but when I detonate the ransomware tools get crash.
@jackymarcel41084 ай бұрын
Martin Scott Garcia Charles Young Anthony
@hydradragonantivirus10 ай бұрын
Malware analysis didn't work anymore.
@AntonMaverick948 ай бұрын
May I know why?
@SerikPoliasc4 ай бұрын
Williams Daniel Williams Karen Clark Thomas
@MuhaiminHamzi Жыл бұрын
Isn't this a paid course?
@cyrusmutua9276 Жыл бұрын
Full course covers up to 9 hours, the first 5 hours are completely free.
@Robalo450 Жыл бұрын
Can anyone get past the "The Installer GUI" where you can select the different packages you want installed? I dont have the option to confirm yes or no and proceed.
@modbat9463 Жыл бұрын
why i cant open the Malware.Unknown.exe ? if i renamed it from .exe.malz to .exe it wont run at all. it says i have to look in the microsoft store to search an app to run it. And could anyone tell me how to get the malware on the vm without compromising my main operating system? Thanks and Great video!