Login Register






Flare-vm - Windows Malware Analysis Distribution filter_list
Author
Message
Flare-vm - Windows Malware Analysis Distribution #1
Welcome to FLARE VM - a fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing, etc.

Please see https://www.fireeye.com/blog/threat-rese...lware.html for a blog on installing and using the FLARE VM.

You are expected to have an existing installation of Windows 7 or above. This allows you to choose the exact Windows version, patch level, architecture and virtualization environment yourself.

Once you have that available, you can quickly deploy the FLARE VM environment by visiting the following URL in Internet Explorer (other browsers are not going to work):

http://boxstarter.org/package/url?https:...alware.ps1

After you navigate to the above URL in the Internet Explorer, you will be presented with a Boxstarter WebLauncher dialog. Select Run to continue the installation as illustrated in Figure 1.

[Image: Fig1.png]

Following successful installation of Boxstarter WebLauncher, you will be presented with a console window and one more prompt to enter your Windows password as shown in Figure 2. Your Windows password is necessary to restart the machine several times during the installation without prompting you to login every time.


[Image: Fig2.png]

The rest of the process is fully automated, so prepare yourself a cup of coffee or tea. Depending on your connection speed, the initial installation takes about 30-40 minutes. Your machine will also reboot several times due to the numerous software installation’s requirements. During the deployment process, you will see installation logs of a number of packages.

Once the installation is complete, it is highly recommended to switch the Virtual Machine networking settings to Host-Only mode so that malware samples would not accidentally connect to the Internet or local network. Also, take a fresh virtual machine snapshot so this clean state is saved! The final FLARE VM installation should look like Figure 3.

[Image: Fig3.png]

Complet tutorial : https://www.fireeye.com/blog/threat-rese...lware.html

Tools:
Debuggers
  • OllyDbg + OllyDump + OllyDumpEx
  • OllyDbg2 + OllyDumpEx
  • x64dbg
  • WinDbg
Disassemblers
  • IDA Free
  • Binary Ninja Demo
Java
  • JD-GUI
  • dex2jar
Visual Basic
  • VBDecompiler
Flash
  • FFDec
.NET
  • ILSpy
  • DNSpy
  • DotPeek
  • De4dot
Office
  • Offvis
[bHex Editors[/b]
  • FileInsight
  • HxD
  • 010 Editor
PE
  • PEiD
  • ExplorerSuite (CFF Explorer)
  • PEview
  • DIE
  • PeStudio
Text Editors
  • SublimeText3
  • Notepad++
  • Vim
Utilities
  • MD5
  • 7zip
  • Putty
  • Wireshark
  • RawCap
  • Wget
  • UPX
  • Process Hacker
  • Sysinternals Suite
  • API Monitor
  • SpyStudio
  • Checksum
  • Unxutils
Python, Modules, Tools
  • Python 2.7
  • Hexdump
  • PEFile
  • Winappdbg
  • FakeNet-NG
  • Vivisect
  • FLOSS
  • FLARE_QDB
  • PyCrypto
  • Cryptography


[Image: Vs4P58c.png]

[+] 2 users Like ZanGetsu's post
Reply

RE: Flare-vm - Windows Malware Analysis Distribution #2
This is a hell of a lot more simpler than setting up each tool by hand, thanks ZanGetsu
[Image: YmmIqHV.gif]
Donations: 1CCR21K2fnu2yAinUTFPsVdY7u4FkjNPs5

Reply

RE: Flare-vm - Windows Malware Analysis Distribution #3
I love the tools.

Along with many other tools, I used to use OllyDbg (with a heap of plugins) & PEiD when reverse engineering applications. That was many years ago. Yet another wonderful contribution, thanks.
[Image: AD83g1A.png]

Reply