In the malware analysis course I teach at SANS Institute, I explain how to reverse-engineer malicious software. It is an interesting, but time-consuming process if you don’t have the right skills and tools at hand. There are several free malware analysis sandboxes and services that can examine malicious artifacts automatically. They can save time and provide an overview of the specimen’s capabilities, so that analysts can decide where to focus their more manual analysis efforts:
- AMAaaS (Android files)
- Any.run (Community Edition)
- Binary Guard True Bare Metal
- Intezer Analyze (Community Edition)
- Comodo Valkyrie
- Detux Sandbox (Linux binaries)
- Joe Sandbox Cloud (Community Edition)
- Malwr (down at the moment)
- SecondWrite (free version)
- Hybrid Analysis
If you’re interested in setting up your own automated malware analysis tools, take a look at my note regarding Free Toolkits for Automating Malware Analysis. These are the services I have come across.
If you know of another reliable and free service I didn’t list, please let me know. My other lists of on-line security resources outline Blocklists of Suspected Malicious IPs and URLs and On-Line Tools for Malicious Website Lookups.