Online Malware Analysis Services & Reading Information 08-25-2014, 05:25 PM
#1
Introduction
In this thread I will talk about the online malware analysis services in which it will scan and basically tell you everything the file does to the computer. I will also be showing you the obvious points to look for in RATs, and Worms which have key points in others like Keyloggers and other Trojans. Yes this is very basic but I want to start from the beginning before creating advanced tutorials on analyzing malware with these sites..
Sites
Anubis - Malware Analysis for Unknown Binaries
Comodo Automated Analysis System
EUREKA - An Automated Malware Binary Analysis Service
Joe Sandbox Document Analyzer (PDF, RTF and MS Office files)
Joe Sandbox File Analyzer
Malwr
ThreatExpert
ThreatTrack
ViCheck
VisualThreat (Android files)
Xandora
XecScan (PDF and MS Office files from targeted attacks)
- I shouldn't have to help you upload or find the right site, do some research.
How to Analyze Files
Remote Administration Tools
1) This is a upload of Dark Comet one of the most popular RATs: http://www.threatexpert.com/report.aspx?...cab09ac7cd
2) Now you see right away scrolling down it allows remote access.
![[Image: w3c6crA.png]](http://i.imgur.com/w3c6crA.png)
3) You also see it running on startup.
![[Image: DsKQfOi.png]](http://i.imgur.com/DsKQfOi.png)
4) And you see this is a skid hiding behind No-IP.
]
Worm
1) These are also very easy to find here is a link: http://www.threatexpert.com/report.aspx?...9ba37f326e
2) As you can see right off the bat it tells you what it is trying to do. Image to wide -> http://i.imgur.com/wFpjnX2.png
3) Now a noob attempt to hide the process from the user, you should never trust a program that tries to immitate another windows process
![[Image: H7FyDiE.png]](http://i.imgur.com/H7FyDiE.png)
4) And finally adds on startup
![[Image: oeJRc4I.png]](http://i.imgur.com/oeJRc4I.png)
Conclusion
If you don't trust the program you should scan it with a Online Malware Analysis Service even though you could be waiting 5 to 10 minutes on the finial analysis it is well worth having your computer fucked and trying to fix it for a hour or more than waiting 10 minutes to see if it is infected or not. The examples were very obvious and I will probably be doing some advanced analysis examples later on but I just wanted everyone the basics before I got onto something advanced.
Also if you have a file you are not sure on send a private message and I will tell if you if the file is safe or not.
In this thread I will talk about the online malware analysis services in which it will scan and basically tell you everything the file does to the computer. I will also be showing you the obvious points to look for in RATs, and Worms which have key points in others like Keyloggers and other Trojans. Yes this is very basic but I want to start from the beginning before creating advanced tutorials on analyzing malware with these sites..
Sites
Anubis - Malware Analysis for Unknown Binaries
Comodo Automated Analysis System
EUREKA - An Automated Malware Binary Analysis Service
Joe Sandbox Document Analyzer (PDF, RTF and MS Office files)
Joe Sandbox File Analyzer
Malwr
ThreatExpert
ThreatTrack
ViCheck
VisualThreat (Android files)
Xandora
XecScan (PDF and MS Office files from targeted attacks)
- I shouldn't have to help you upload or find the right site, do some research.
How to Analyze Files
Remote Administration Tools
1) This is a upload of Dark Comet one of the most popular RATs: http://www.threatexpert.com/report.aspx?...cab09ac7cd
2) Now you see right away scrolling down it allows remote access.
![[Image: w3c6crA.png]](http://i.imgur.com/w3c6crA.png)
3) You also see it running on startup.
![[Image: DsKQfOi.png]](http://i.imgur.com/DsKQfOi.png)
4) And you see this is a skid hiding behind No-IP.
]Worm
1) These are also very easy to find here is a link: http://www.threatexpert.com/report.aspx?...9ba37f326e
2) As you can see right off the bat it tells you what it is trying to do. Image to wide -> http://i.imgur.com/wFpjnX2.png
3) Now a noob attempt to hide the process from the user, you should never trust a program that tries to immitate another windows process
![[Image: H7FyDiE.png]](http://i.imgur.com/H7FyDiE.png)
4) And finally adds on startup
![[Image: oeJRc4I.png]](http://i.imgur.com/oeJRc4I.png)
Conclusion
If you don't trust the program you should scan it with a Online Malware Analysis Service even though you could be waiting 5 to 10 minutes on the finial analysis it is well worth having your computer fucked and trying to fix it for a hour or more than waiting 10 minutes to see if it is infected or not. The examples were very obvious and I will probably be doing some advanced analysis examples later on but I just wanted everyone the basics before I got onto something advanced.
Also if you have a file you are not sure on send a private message and I will tell if you if the file is safe or not.
![[Image: Sigger.png]](http://s30.postimg.org/vqhkob475/Sigger.png)

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)

