Best Malware Analysis Tools | Learn Malware Analysis

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ธ.ค. 2024

ความคิดเห็น • 100

  • @abdlerhmanmohamed438
    @abdlerhmanmohamed438 4 ปีที่แล้ว +7

    i was waiting for this video, some people mentioned that in ur videos,
    glad u listened bro

  • @TDawgS117
    @TDawgS117 4 ปีที่แล้ว +6

    This is a fantastic rundown of tools to start with in metadata and malware analysis. Thank you so much for making a video about these, this will help me in my studies!!

  • @Dmwntkp99
    @Dmwntkp99 4 ปีที่แล้ว +11

    One of the most useful channels with a pleasant voice👍

    • @erwynnipegerwynnipeg8455
      @erwynnipegerwynnipeg8455 4 ปีที่แล้ว

      Agreed, his voice is cute lmao.

    • @dxfvgyhjh
      @dxfvgyhjh 4 ปีที่แล้ว

      And last but not least he speaks real ENGLISH

  • @JohnAtkinson-ww8qe
    @JohnAtkinson-ww8qe ปีที่แล้ว

    Hello brother. I have been watching alot of your videos here lately after being a victem of a really bad malware attack. I ended up having to reset my laptop back to factory settings. I wish I would have found your content sooner. I am learning alot from your videos for tips on how to prevent it from happening again. Dropped you a sub. Keep the content coming.

  • @metehangunaydn6295
    @metehangunaydn6295 4 ปีที่แล้ว +3

    Thanks for suggestions, Leo. After watching this video, i noticed that i had used most of them (1 or 2 tools missing which i didn't use beforehand)(I even used Ghidra :) ). I can also recommend comodo cleaning essentials' kiill switch and autorun analyzer tools, and also quick repair tool. Thanks for your videos, again.. :)

  • @Wshocker
    @Wshocker 4 ปีที่แล้ว

    In addition to Sysinternals tools. I use WinDbg, APIMonitor and even Windows Performance Recorder and Analyzer to understand what an application is doing.

  • @ajorge_yul
    @ajorge_yul ปีที่แล้ว

    Thanks!

  • @wezelesworth
    @wezelesworth 4 ปีที่แล้ว +64

    Hey Leo, have you ever seen a piece of sophisticated malware attempt to evade virtualization software and infect the host system?

    • @pcsecuritychannel
      @pcsecuritychannel  4 ปีที่แล้ว +53

      Yes. They are rare though.

    • @Sonic-ww6wm
      @Sonic-ww6wm 4 ปีที่แล้ว +1

      @@pcsecuritychannel try pchunter and do a review if you find it good

    • @justnaturalcake1
      @justnaturalcake1 ปีที่แล้ว +1

      @what lol or raspberry pi

  • @lolcorporation7308
    @lolcorporation7308 4 ปีที่แล้ว +6

    Any reason why you still use ollydbg over x64dbg.

  • @aaandag9688
    @aaandag9688 4 ปีที่แล้ว +7

    Is Windows 10 Pro's Hyper-V good/secure enough for malware testing? Is VirtualBox or Vmware safer?

    • @xuriajiva
      @xuriajiva 4 ปีที่แล้ว +4

      Both are hypervisors, so a virtual machine is created that is independent of the main system. your decision is only whom do you want to trust more? who has fewer bugs in their program that could be exploited by malware? but in general both are equally good.

    • @malwaretestingfan
      @malwaretestingfan 4 ปีที่แล้ว

      VMWare and VirtualBox are safer.

    • @encrypt3d587
      @encrypt3d587 4 ปีที่แล้ว +1

      @Lukasz That's terrible for performance, and that's if you ignore that nested virtualization support isn't always present or practical. Also, if you're using the same program for both VMs, then any VM escape bugs would still allow it to work its way into your system.

  • @MrBrianSchumacher
    @MrBrianSchumacher 4 ปีที่แล้ว +1

    Excellent review. Thank you.

  • @hrishikeshkshirsagar6738
    @hrishikeshkshirsagar6738 2 ปีที่แล้ว

    Awesome video, you are a champ.. Cheers

  • @TanaseLiviu
    @TanaseLiviu 4 ปีที่แล้ว

    Extraordinary ! Thanks guys - I enjoyed .

  • @nhanNguyen-wo8fy
    @nhanNguyen-wo8fy 3 ปีที่แล้ว

    3:45 process monitor

  • @ultralaggerREV1
    @ultralaggerREV1 4 ปีที่แล้ว +2

    Ok, but how are we gonna know which file is a malware?
    Like SVCHOST skyrockets to 100% Disk for no apparent reason and I don’t want to erase SVCHOST because it’s crucial for my Windows 10 and SVCHOST is made by Microsoft and I don’t know how can I determine if there is a malware inside SVCHOST. It’s what I want to know... Now recently I PAUSED windows 10 updates (I PAUSED them temporarily) but why am I seen a process called “Windows modules installer worker” next to “Windows Update” and “Edge Installer” (note that I already have the new Edge installed and I don’t know why is there such process of “edge installer” when I already have it, what is it installing? Malware?!) and these skyrocket for NO REASON. I have updates paused but these processes are consuming high Disk usage when it’s strange, nothing is updating and nothing is being installed!!! Are these viruses?!

  • @Windows11Official
    @Windows11Official 4 ปีที่แล้ว +15

    To be honest, I kind of prefer any.run more

    • @user-xw6fg5pi8q
      @user-xw6fg5pi8q 4 ปีที่แล้ว +1

      Pretty bad if you dont want to get your sample on the wild.

    • @KurtisQu
      @KurtisQu 3 ปีที่แล้ว

      problem is it doesn’t support windows 10, 11 for free

  • @elviraeloramilosic9813
    @elviraeloramilosic9813 4 ปีที่แล้ว +1

    Perfect. 👌🏻👍🏻
    Thanks.

  • @alexandermoev9395
    @alexandermoev9395 4 ปีที่แล้ว +1

    I love your youtube channel

  • @redeyes057
    @redeyes057 4 ปีที่แล้ว

    thankyou sir. helps a lot and learn a lot

  • @goufbam
    @goufbam 4 ปีที่แล้ว +1

    i forgot the program name but you could record opening a exe file and then record what it does and where it injects into another exe for example running a exe and that exe having a RAT and then injecting into svchost.exe, if anyone could help me find it that be great!

    • @BarafuAlbino
      @BarafuAlbino 4 ปีที่แล้ว

      @Kaden any.run: 90$/month or all 64bit malware ignored.

    • @goufbam
      @goufbam 4 ปีที่แล้ว

      Used to be a program that did that hmm

    • @davet5223
      @davet5223 4 ปีที่แล้ว

      Cuckoo Sandbox?

  • @malwaretestingfan
    @malwaretestingfan 4 ปีที่แล้ว

    Pretty cool video, i will check some.

  • @augusto3045
    @augusto3045 4 ปีที่แล้ว +7

    726/5000
    Hi Leo, I was a user for 4 years practically of Emsisoft Antimalware and I loved it all the time but currently the price of it has gone up a lot and I will not renew with them unfortunately I intend to migrate to Kaspersky Security Cloud Free, in fact I have even removed it (Emsisoft) of my PCs but my Emsisoft license has not yet expired, I was wondering if before the date expires they send me an email to be able to cancel the subscription since I haven't seen anything on the website on how to do it even in my account? ! Could you tell me about it? Otherwise, I will have to send an email to Emsisoft. Their support is really good, but recently I realized that Emsisoft is bad at detecting viruses in memory. Kaspersky catches on time.

  • @MrRaja
    @MrRaja 2 ปีที่แล้ว

    So can i use PEstudio and just throw in a trojan without it running on my system?

  • @rraygen
    @rraygen 4 ปีที่แล้ว +2

    Hey I was thinking recently, what are your thoughts about the integrated Windows 10 Sandbox VM? Worth the comfort or better stick to the classic VMs?

  • @mksuenone
    @mksuenone 3 ปีที่แล้ว

    Hi i have problem on my pc. It was penetrated by .URNB file ransomware. Can you help me with this?

  • @firasbe3866
    @firasbe3866 2 ปีที่แล้ว

    Hi, sometimes i use virustotal and it detects malware but it says no sandboxes flagged this file, what that means?

  • @Martin-ot7xj
    @Martin-ot7xj 4 ปีที่แล้ว

    Hi there,how we can find the port we got attacked, for example we have one pc and we got virus or attack from Internet, how we can to know from which port we got attacked?? From which Specific port we received virus or attack?? Thnx

  • @donaldduck6198
    @donaldduck6198 4 ปีที่แล้ว

    MS Office: some crooks can put VBA into a xlsx. How to detect? It is "purged", i.e. the P-Code is deleted/never included. Do you have a hint or link?

  • @weso-ht3sy
    @weso-ht3sy 4 ปีที่แล้ว

    Quick question. What's the best antivirus for rate of protection?

  • @35Darkstorm
    @35Darkstorm 4 ปีที่แล้ว +1

    Hey leo, can you do a vid on spyhunter vs malware please?

  • @viniciusnoyoutube
    @viniciusnoyoutube 4 ปีที่แล้ว

    Great video.
    Thanks.

  • @tiagomarante7720
    @tiagomarante7720 4 ปีที่แล้ว

    Hey, do you know any tool for virus analysis using terminal? If so can you say the name I need to automate some stuff and that would be good .

  • @yes-vl7gh
    @yes-vl7gh 4 ปีที่แล้ว +5

    make more videos pls

  • @uppblissed
    @uppblissed 3 ปีที่แล้ว

    im curious bout where you finding these wallpapers

  • @AmusedBeaver-vq2hw
    @AmusedBeaver-vq2hw 8 หลายเดือนก่อน

    can you help me with .looy decrypter

  • @satheshname8983
    @satheshname8983 4 ปีที่แล้ว

    My laptop and mobile is infected with malware how can i do analyis to catch the hacker and clean them

  • @glassware
    @glassware 4 ปีที่แล้ว

    I only use Process Hacker to cheat in csgo because it haves option to inject dll
    But nice video

  • @ethimself5064
    @ethimself5064 4 ปีที่แล้ว +2

    The first program looks quite scary for me, I go places where I should not go and my System Restore no longer works. Hahaha, think I will pass on the first one.

    • @david3994
      @david3994 4 ปีที่แล้ว

      The tools are for virtual machines as you don’t infect your main host.

  • @sci-figeek9192
    @sci-figeek9192 4 ปีที่แล้ว

    Hello PC Security Channel new member to your channel is process hacker safe to use the reason i am asking is norton say its not safe and delete it

    • @sci-figeek9192
      @sci-figeek9192 4 ปีที่แล้ว

      ok good to know you rely to your new subscribe that made up my mind then

  • @tudor6766
    @tudor6766 4 ปีที่แล้ว

    Hello Leo, can you tell me what vpn you are using or if you are using one
    Also, were can I get a automation tool similar to malex?
    Thanks in advance and I want to let you know that I love your content!

  • @augusto3045
    @augusto3045 4 ปีที่แล้ว

    Hi Léo, can you test 360 Total Security Essentials, i Know is chinese and i dont like products chinese but just for see if hes good in test please test the Essential just not the other have a lot of things... Thanks

  • @saif-pm6eh
    @saif-pm6eh 4 ปีที่แล้ว

    Nice video ,could you please make a video about shadow defender I'm using it only when I try to install any suspicious software ,tool,etc I found something like bug or vulnerability with it , some tool like kmspico can activate windows even if shadow defender is on active mode can you please explain why this happen Thank you

  • @daywithislam9219
    @daywithislam9219 4 ปีที่แล้ว

    brother...make a video with avast vs malwar

  • @crepituss9381
    @crepituss9381 3 ปีที่แล้ว

    I know this is 6 mos old, but I would be interested in a video of what you think about Cuckoo automated malware analysis sandbox.

  • @Sva010
    @Sva010 2 ปีที่แล้ว

    process hacker gpu usage are works only on windows 7

  • @adventkloud4571
    @adventkloud4571 3 ปีที่แล้ว

    Is the discord link broken?

  • @nftshiller8485
    @nftshiller8485 ปีที่แล้ว

    do you still use this today or is there a new one

  • @kx500cc
    @kx500cc 4 ปีที่แล้ว

    Mucjas gracias por el aporte !!!!

  • @SkyFly19853
    @SkyFly19853 4 ปีที่แล้ว +2

    Is it only for Windows?
    Or there is a Linux version as well?

    • @rraygen
      @rraygen 4 ปีที่แล้ว

      Windows. But if you google " linux" you can find alternatives

    • @SkyFly19853
      @SkyFly19853 4 ปีที่แล้ว

      @@rraygen
      That's why I asked before I ever research...

  • @IEnjoyCreatingVideos
    @IEnjoyCreatingVideos 4 ปีที่แล้ว

    Great video Leo! Thanks for sharing it with us💖🐤👍👌😎JP

  • @bantymech8242
    @bantymech8242 4 ปีที่แล้ว

    These many days I missed your channel, where have you gone mate?????????? 😄
    Thanks for your amazing videos, I am learning much from you. Recently I have started using Autoruns and process explorer

  • @mauriciorodriguez67
    @mauriciorodriguez67 4 ปีที่แล้ว

    could be nice to show these tools in a malware case

  • @darkestknightishere
    @darkestknightishere 3 ปีที่แล้ว

    👍ed , subscribed, 🔔

  • @countdracowo
    @countdracowo 4 ปีที่แล้ว

    Hey leo. Can you give me an example on a virus that tries to attack the host system whilst running on a virtual machine?
    And they do it through the shared folder right?

    • @countdracowo
      @countdracowo 4 ปีที่แล้ว

      And btw thank you for this video!

  • @ROHITNB100
    @ROHITNB100 3 ปีที่แล้ว

    Great 👍

  • @Menalix
    @Menalix 4 ปีที่แล้ว

    Ollydbg lawl? haven't you heared of x64dbg?

  • @dunelson1824
    @dunelson1824 4 ปีที่แล้ว

    InstallWatch, something like regshot in this video.

  • @beatzbye
    @beatzbye 2 ปีที่แล้ว

    It sounds all complicated I need some help

  • @lokelaufeyson9931
    @lokelaufeyson9931 3 ปีที่แล้ว

    Opened the video to find good tools to track traffic but "owned by microsoft" made me sad. If i want to track microsoft communication and if they own the program they will hide that communication in their program.. we all know they will do that, we all know microsoft and how they work

  • @vendybirdsvadl7472
    @vendybirdsvadl7472 4 ปีที่แล้ว +1

    not first, not last, not middle and noone should care

    • @barkingmad7407
      @barkingmad7407 2 ปีที่แล้ว

      With much more than a bunch of Uh-Huh, and a whole lotta' Oh-Yeah: Brilliant. 10/10.

  • @haroldvonhelms8304
    @haroldvonhelms8304 4 ปีที่แล้ว

    who stops hacker best for pc security

  • @ivanguerra1260
    @ivanguerra1260 4 ปีที่แล้ว

    I didn´t understand, this video says how you can see the maleware in your system, but, How to remove it automaticlly ?

    • @erwynnipegerwynnipeg8455
      @erwynnipegerwynnipeg8455 4 ปีที่แล้ว

      This isnt about how to remove malware. This is how to look at malware. You will be best looking somewhere else if you want to remove it.

  • @TheKillerZmile
    @TheKillerZmile 4 ปีที่แล้ว +4

    So i figured out that *HITMAN PRO removal tool* gave me malware or something its weird asf A malware removal tool giving me malware how ironic lmao
    the malware deleted my kaspersky and zemana antimalware and disabled my windows defender (the only left was Security at glance screen) and windows update gives error
    then i just clean install windows 10 and installed kaspersky and zemana and hitmanpro
    and then i got the same fcking malware all over again!!
    so you know what fck this im going to clean install windows 10 again and only install Kaspersky
    and as of today i dont have any malware.
    *NEVER GONNA INSTALL HITMAN PRO*
    PS.
    i dont have any pirated softwares,games etc.
    i have genuine legit windows 10 pro
    legit games.

  • @michelvilleneuve
    @michelvilleneuve 4 ปีที่แล้ว +1

    the best malware protection is to get the malware creator to stop doing the malware. People that can not live in an honest society.