DIY Malware Analysis Lab for Free (with CrackMe Challenge!) | master0Fnone Ep. 2.1: Sandbox in a Box

Ғылым және технология

(Part 1 of 2)
If you've ever wanted to analyze malware on your own without spending a fortune, this is your time.
In this free master0Fnone class, you will learn to:
1. Build a simple malware analysis lab for FREE, using 2 virtual machines (Remnux and Windows 10) and several free analysis and monitoring tools
2. Snapshot your lab and make it exportable so you can bring it anywhere
3. Examine some real malware samples in your newly-built sandbox, test out the tools we installed, and discover how to pull indicators of compromise and artifacts for detections and determining what the malware is trying to accomplish
4. Challenge you to take what you've learned and use it to achieve an entry on the "Wall of Fame" by analyzing the included "CrackMe" program and finding all the flags!
The jeFF0Falltrades master0Fnone Class series is a collection of free online courses dedicated to making learning complex topics - like malware analysis - more accessible (and fun) to everyone.
Please leave feedback and questions here as comments, or DM me on Mastodon (social links listed on the channel).
Check the pinned comment for any updates to the content.
Let me know what you would like to see in future videos!
Project Homepage and CrackMe Challenge Instructions: github.com/jeFF0Falltrades/Tu...
CrackMe Challenge Form: forms.gle/nE2yFZowxhCKBPw37
Thank you to these incredible artists whose works were featured in this video:
Thumbnail image derived from this work by gstudioimagen1 on Freepik
www.freepik.com/free-vector/v...
Intro Music from #Uppbeat (free for Creators!):
uppbeat.io/t/monument-music/m...
License code: ZD860DLJBOAVDIIH
Intro Music from #Uppbeat (free for Creators!):
uppbeat.io/t/soundroll/transcend
License code: YMTA0L5AOB19X1SV
00:00:00 - Sarcastic Intro & Unsarcastic Apology
00:02:57 - Course Overview
00:05:35 - Important Notes
00:07:57 - Part 1 Start/VirtualBox install
00:11:55 - Importing/Configuring Remnux
00:15:29 - Detour: FLARE-VM
00:16:55 - Remnux VM settings
00:20:35 - VirtualBox Guest Additions (Remnux)
00:21:57 - Accessing shared folders (Remnux)
00:22:58 - Upgrading/Updating Remnux
00:23:47 - Detour: Validating our network connection
00:25:54 - Custom tools/parse_hashes.sh
00:32:35 - the RAT King Parser
00:33:37 - INetSim configuration
00:38:36 - Creating our virtual network
00:46:29 - Burpsuite/INetSim troubleshooting & setup
00:52:12 - Finishing our Remnux machine
00:53:32 - our Windows VM/troubleshooting
01:02:00 - Disabling Windows Update
01:04:00 - pafish (Paranoid Fish) & VBoxCloak
01:11:48 - Disabling Windows Defender & Firewall
01:16:46 - Networking setup (Windows)
01:18:17 - Testing HTTPS traffic capture w/ the Burpsuite root certificate
01:23:43 - Creating the final Clean snapshot for Remnux
01:25:33 - Ghidra/JDK/Python/7Zip & Revealing hidden files/folders/extensions
01:31:43 - IDA Free
01:32:45 - x64dbg
01:34:06 - System Informer/Process Hacker
01:35:25 - Process Monitor
01:36:41 - Chrome
01:37:08 - Wireshark
01:39:57 - LibreOffice/Setting macro security
01:44:07 - .NET 8.0 SDK
01:44:30 - dnSpy
01:46:05 - Capture-Py
01:48:27 - Detect-It-Easy
01:50:05 - de4dot
01:52:21 - pe-sieve
01:54:10 - VbsEdit
01:55:11 - CMD Watcher
01:57:23 - ProcessSpawnControl
02:00:30 - Exporting VMs/Last-minute crises/troubleshooting
02:07:31 - Disabling Edge running in background
02:08:50 - Cleanup and final snapshots
02:10:20 - False ending/fixing procmon
02:11:28 - Congratulations! End of Episode 2.1

Пікірлер: 16

  • @jeFF0Falltrades
    @jeFF0Falltrades25 күн бұрын

    To my loyal and wonderful subs: I apologize again for the delay on this one - our 10,000 sub celebration is now an 11,000 sub celebration, which is awesome, but I am sorry it took this long to push this out and I hope the wait was worth it ❤️ Check this pinned comment for corrections and updates and thanks for watching! EDIT: Thanks to @BrakeSec for the suggestion, I added a simple helper script so you don't have to worry about commenting out the netplan configuration yourself; It's added to the repo!

  • @CrusaderMen
    @CrusaderMen25 күн бұрын

    Thank you I love your content

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    @@CrusaderMen Thank *you*! I hope you enjoy this one too

  • @lukefidalgo8154
    @lukefidalgo815425 күн бұрын

    Just as I bought Practical Malware Analysis (the alien book), this video comes out! Some really good timing! :P

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    YES!!! I'm so happy for you because that book is a treat. And you'll find my set up is very akin to the one in the book, so I hope this complements it well :-). Also, if you're interested, No Starch Press just this month came out with another book called "Evasive Malware" that I call out in this video. I haven't read through all of it yet, but what I have read has been really good! Thanks for watching and I hope you enjoy both this and PMA!

  • @Jarvx

    @Jarvx

    13 күн бұрын

    The alien book is top tier :)

  • @0ri0nexe
    @0ri0nexe25 күн бұрын

    The king posted ! Stop what ur doing and open your best disassembler ;) Jokes aside i like how you introduction more and more useful tools each video

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    @@0ri0nexe Man you made my day hahaha. I’m in the middle of finishing up editing Part 2 (which I can say DEFINITIVELY will be out tomorrow AM, Eastern Time), and I really needed this motivation. Thanks for being a great hype man and I am glad you find the tools useful! I’m so happy to finally share my lab setup as it’s been good to me all these years.

  • @0ri0nexe

    @0ri0nexe

    25 күн бұрын

    ​@@jeFF0Falltrades Two videos in a row, what a time to be alive.

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    @@0ri0nexe 🤣

  • @micha7863
    @micha786325 күн бұрын

    Great job! Appreciate it veeery much. Also congrats on becoming a dad. BTW: I have tested VBox 7 Unattended installation for Win10 and I always had problems with the VM - freezes/slow running (problem is confirmed by other users having the same issue).

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    Thanks so much on both accounts, and thanks for being here!

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    @@micha7863 thanks for attesting to the unattended installation stuff as well - as you’ll see (if you haven’t already) it DOES cause issues for me as well 🥴

  • @micha7863

    @micha7863

    25 күн бұрын

    @@jeFF0Falltradesoh ok, i was commenting while watching, thanks again!

  • @jeFF0Falltrades

    @jeFF0Falltrades

    25 күн бұрын

    I figured haha. Didn't mean to spoil it for you, but yeah, had quite a few "live" troubleshooting instances with VirtualBox/Windows

Келесі