Flare-vm - Windows Malware Analysis Distribution 10-04-2017, 02:51 PM
#1
Welcome to FLARE VM - a fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing, etc.
Please see https://www.fireeye.com/blog/threat-rese...lware.html for a blog on installing and using the FLARE VM.
You are expected to have an existing installation of Windows 7 or above. This allows you to choose the exact Windows version, patch level, architecture and virtualization environment yourself.
Once you have that available, you can quickly deploy the FLARE VM environment by visiting the following URL in Internet Explorer (other browsers are not going to work):
http://boxstarter.org/package/url?https:...alware.ps1
After you navigate to the above URL in the Internet Explorer, you will be presented with a Boxstarter WebLauncher dialog. Select Run to continue the installation as illustrated in Figure 1.
Following successful installation of Boxstarter WebLauncher, you will be presented with a console window and one more prompt to enter your Windows password as shown in Figure 2. Your Windows password is necessary to restart the machine several times during the installation without prompting you to login every time.
The rest of the process is fully automated, so prepare yourself a cup of coffee or tea. Depending on your connection speed, the initial installation takes about 30-40 minutes. Your machine will also reboot several times due to the numerous software installation’s requirements. During the deployment process, you will see installation logs of a number of packages.
Once the installation is complete, it is highly recommended to switch the Virtual Machine networking settings to Host-Only mode so that malware samples would not accidentally connect to the Internet or local network. Also, take a fresh virtual machine snapshot so this clean state is saved! The final FLARE VM installation should look like Figure 3.
Complet tutorial : https://www.fireeye.com/blog/threat-rese...lware.html
Tools:
Debuggers
Please see https://www.fireeye.com/blog/threat-rese...lware.html for a blog on installing and using the FLARE VM.
You are expected to have an existing installation of Windows 7 or above. This allows you to choose the exact Windows version, patch level, architecture and virtualization environment yourself.
Once you have that available, you can quickly deploy the FLARE VM environment by visiting the following URL in Internet Explorer (other browsers are not going to work):
http://boxstarter.org/package/url?https:...alware.ps1
After you navigate to the above URL in the Internet Explorer, you will be presented with a Boxstarter WebLauncher dialog. Select Run to continue the installation as illustrated in Figure 1.
![[Image: Fig1.png]](https://www.fireeye.com/content/dam/fireeye-www/blog/images/FLARE%20VM/Fig1.png)
Following successful installation of Boxstarter WebLauncher, you will be presented with a console window and one more prompt to enter your Windows password as shown in Figure 2. Your Windows password is necessary to restart the machine several times during the installation without prompting you to login every time.
![[Image: Fig2.png]](https://www.fireeye.com/content/dam/fireeye-www/blog/images/FLARE%20VM/Fig2.png)
The rest of the process is fully automated, so prepare yourself a cup of coffee or tea. Depending on your connection speed, the initial installation takes about 30-40 minutes. Your machine will also reboot several times due to the numerous software installation’s requirements. During the deployment process, you will see installation logs of a number of packages.
Once the installation is complete, it is highly recommended to switch the Virtual Machine networking settings to Host-Only mode so that malware samples would not accidentally connect to the Internet or local network. Also, take a fresh virtual machine snapshot so this clean state is saved! The final FLARE VM installation should look like Figure 3.
![[Image: Fig3.png]](https://www.fireeye.com/content/dam/fireeye-www/blog/images/FLARE%20VM/Fig3.png)
Complet tutorial : https://www.fireeye.com/blog/threat-rese...lware.html
Tools:
Debuggers
- OllyDbg + OllyDump + OllyDumpEx
- OllyDbg2 + OllyDumpEx
- x64dbg
- WinDbg
- IDA Free
- Binary Ninja Demo
- JD-GUI
- dex2jar
- VBDecompiler
- FFDec
- ILSpy
- DNSpy
- DotPeek
- De4dot
- Offvis
- FileInsight
- HxD
- 010 Editor
- PEiD
- ExplorerSuite (CFF Explorer)
- PEview
- DIE
- PeStudio
- SublimeText3
- Notepad++
- Vim
- MD5
- 7zip
- Putty
- Wireshark
- RawCap
- Wget
- UPX
- Process Hacker
- Sysinternals Suite
- API Monitor
- SpyStudio
- Checksum
- Unxutils
- Python 2.7
- Hexdump
- PEFile
- Winappdbg
- FakeNet-NG
- Vivisect
- FLOSS
- FLARE_QDB
- PyCrypto
- Cryptography
![[Image: Vs4P58c.png]](https://i.imgur.com/Vs4P58c.png)






![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


![[Image: YmmIqHV.gif]](https://i.imgur.com/YmmIqHV.gif)










