- Malware Analysis Joining Minerva Labs to Keep Malware in Check
Anti-malware products can employ deception-based approaches, such as fooling malware into thinking it's running in an analysis sandbox or simulating infection markers that specimens check to avoid...
- Malware Analysis How to Share Malware Samples With Other Researchers
Sharing malware samples with other researchers requires password-protecting archives with passwords like "infected" or "malware" to get past antivirus scanners. Using the 7-Zip format with encrypted...
- Malware Analysis Version 6 Release of the REMnux Linux Distro for Malware Analysis
REMnux v6 updates existing malware analysis tools and introduces new ones including pedump, VolDiff, Rekall, oletools, and Docker support. Built on Ubuntu 14.04 64-bit with Debian packages, users can...
- Malware Analysis Contemplating Malware Vaccination via Infection Markers
Some malware checks for infection markers like mutexes, registry keys, or processes to avoid infecting systems twice. Preemptively creating these markers can vaccinate systems against specific...
- Malware Analysis Getting to Know Jan Miller and His Hybrid Malware Analysis Sandbox
Combining static and dynamic analysis in malware sandboxes extracts more artifacts and indicators than pure runtime behavior observation alone. This "hybrid analysis" approach addresses...
- Malware Analysis Version 5 Release of the REMnux Linux Distro for Malware Analysis
REMnux v5 adds tools for examining browser malware, document files, encoded artifacts, network interactions, and Linux specimens. New additions include Thug honeyclient, AnalyzePDF, XORStrings,...