Exploring the Latest Malware Samples

Exploring the Latest Malware Samples

Source: YouTube · John Hammond · published Sep 26, 2023 · 15:22

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates using Any Run, a free online sandbox, to analyze various malware samples and understand their behavior 0:00-0:30.

Key Takeaways:
• Any Run sandbox allows dynamic analysis of malware samples like Redline and SteelC info stealers, extracting configuration data and showing C2 communications 0:33-1:01
• The platform analyzes WannaCry ransomware, revealing how it encrypts files and executes through batch scripts and VBS files 5:21-5:59
• Any Run's interactive environment enables defensive techniques, such as modifying registry settings to disable Windows Script Host and prevent malicious script execution 8:03-9:47
• The tool analyzes various malware delivery methods including Office documents with macros, PowerShell scripts, and jscript files 11:16-13:25

Any Run provides free access to malware analysis capabilities, allowing researchers to safely examine malicious samples without needing static analysis tools.

Sources:

  • 0:00-0:30 Introduction to analyzing malware samples in Any Run
  • 0:33-1:01 Analysis of info stealers showing C2 communications
  • 5:21-5:59 WannaCry ransomware behavior analysis
  • 8:03-9:47 Disabling Windows Script Host as defensive technique
  • 11:16-13:25 Analysis of various malware delivery methods

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

let's take a look at some of the latest malware samples being analyzed on the internet oh look at that right on the top of the list kind of an interesting one looks like it's going to this URL kyleowen.top and vpn.exe which is a Windows executable and it's got a couple tags here for steel c like one of the well-known Steelers and loader oski I'm not sure what those are but it has a lot of these tidbits here action similar to stealing personal data so certainly an infostealer downloads an executable file and there's a whole lot going on so let's take a look so the process is outlined here vpn.exe certainly malicious hey start cmd.exe for self-deleting loads dropped or Rewritten executables and steals credentials from web browsers etc etc actually it has the CFG icon so it might have been ab…