Malware Analysis Bootcamp - File Type Identification

แชร์
ฝัง
  • เผยแพร่เมื่อ 11 ส.ค. 2019
  • Welcome to the Malware Analysis Bootcamp. We will be covering everything you need to know to get started in Malware Analysis professionally. In this video, we will be taking a look at file type identification, why it is important and the tools we will be using.
    Link to slides: docs.google.com/presentation/...
    Malware Sample: s3.eu-central-1.amazonaws.com...
    Tools & links used in the video:
    Windows VM's: developer.microsoft.com/en-us...
    Fireye installation guide: www.fireeye.com/blog/threat-r...
    Github Repository: github.com/fireeye/flare-vm
    ◼️Get Our Courses:
    Python For Ethical Hacking: www.udemy.com/python-for-ethi...
    Ethical Hacking Bootcamp: www.udemy.com/the-complete-et...
    ◼️Our Platforms:
    Blog: hsploit.com/
    HackerSploit Forum: hackersploit.org/
    HackerSploit Cybersecurity Services: hackersploit.io
    HackerSploit Academy: www.hackersploit.academy
    HackerSploit Discord: / discord
    HackerSploit Podcast: / hackersploit
    iTunes: itunes.apple.com/us/podcast/t...
    ◼️Support us by using the following links:
    NordVPN: nordvpn.org/hacker
    Patreon: / hackersploit
    I hope you enjoy/enjoyed the video.
    If you have any questions or suggestions feel free to post them in the comments section or on my social networks.
    Social Networks - Connect With Us!
    -------------------------------
    Facebook: / hackersploit
    Twitter: / hackersploit
    Instagram: / hackersploit
    Patreon: / hackersploit
    --------------------------------
    Thanks for watching!
    Благодаря за гледането
    Kiitos katsomisesta
    Danke fürs Zuschauen!
    感谢您观看
    Merci d'avoir regardé
    دیکھنے کے لیے شکریہ
    देखने के लिए धन्यवाद
    Grazie per la visione
    Gracias por ver
    شكرا للمشاهدة
    #MalwareAnalysis
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 45

  • @m1k3thirteen81
    @m1k3thirteen81 2 ปีที่แล้ว +7

    You are the David Attenborough of Cybersecurity! Can’t get enough! Thank you so much for what you do for the community!

    • @HackerSploit
      @HackerSploit  2 ปีที่แล้ว

      That is greatly appreciated, I am glad you find value in the content.

  • @cherubrock222
    @cherubrock222 4 ปีที่แล้ว

    Amazing series! You have a great way of explaining this stuff.

  • @eswar5252
    @eswar5252 3 ปีที่แล้ว

    Thanks You saved me a lot of time and drew me out of confusion of what to learn

  • @95Biswajit
    @95Biswajit 4 ปีที่แล้ว

    Loved it. :).. looking forward to get more in this series.

  • @VipulVaibhaw
    @VipulVaibhaw 4 ปีที่แล้ว

    Watched it over minutely... thanks for this. :)

  • @sametsahin-eh3qj
    @sametsahin-eh3qj ปีที่แล้ว

    You sir are a genius. Huge respect.

  • @Chris-ez1ly
    @Chris-ez1ly 2 ปีที่แล้ว

    Great video. Thank you as always.

  • @Naveenbabuborugadda
    @Naveenbabuborugadda ปีที่แล้ว

    This is the ratest video about Malware Analysis in TH-cam

  • @amoghnath3330
    @amoghnath3330 4 ปีที่แล้ว

    Thanks waiting for this :)

  • @hanial-hayyawi4578
    @hanial-hayyawi4578 11 หลายเดือนก่อน

    Splendid video

  • @ecliptic_at
    @ecliptic_at 20 ชั่วโมงที่ผ่านมา

    great video

  • @heavenonearth8
    @heavenonearth8 ปีที่แล้ว

    Thank you.

  • @rayamoooooo685
    @rayamoooooo685 2 ปีที่แล้ว

    thanks

  • @KishorKumar-re2rs
    @KishorKumar-re2rs 4 หลายเดือนก่อน

    Can you please explain what is the entry point and what are its uses?

  • @puneetkulkarni2416
    @puneetkulkarni2416 3 ปีที่แล้ว

    Hello Hackersploit!!! You think I should refer to the book Malware Analysis by Monappa KA?
    Which one did you refer?

  • @nikhilt3755
    @nikhilt3755 4 ปีที่แล้ว +3

    "this program cannot be run in DOS"
    this is located inside DOS stub
    if you are running on DOS this header is identified and gets executed
    else its skips this header
    last 16 bits in MZ header tells the address to the PE header
    (because DOS header gets skipped in windows 10)
    my old memories with malware analysis

    • @HackerSploit
      @HackerSploit  4 ปีที่แล้ว

      Yes, we have not yet covered headers yet. This will also be explained.

    • @nikhilt3755
      @nikhilt3755 4 ปีที่แล้ว

      @@HackerSploit ok bro
      i m just saying what i remembered
      its been long while i have learnt
      waiting for whole tuts

  • @christojojo6590
    @christojojo6590 7 หลายเดือนก่อน

    Hi, if the cff explorer can find all the info about the file type, then what is the need for all other tools explained in the video(Hexeditor,exeinfo PE)

  • @nitczi706
    @nitczi706 2 ปีที่แล้ว

    I'm trying to download the Pestudio manually, but when i run it, it says "The version of this file is not compatible with the version of Windows you're running. Check your computer's system information to see whether you need an x86 (32-bit) or x64 (64-bit) version of the program, and then contact the software publisher."
    I tried to find another version to download but I have no success. What can i do? There's another program which could replace the PEstudio?

  • @austinmurphy9074
    @austinmurphy9074 4 ปีที่แล้ว

    doesn't host-only adapter allow guest to communicate with host? How is this safe?

  • @B14CK.M4M84
    @B14CK.M4M84 4 ปีที่แล้ว

    ❤❤👍👍

  • @blade1551431
    @blade1551431 4 ปีที่แล้ว +2

    link for sample does not work for me

  • @supratickdey7125
    @supratickdey7125 3 ปีที่แล้ว

    then how to find file type for packed ones

  • @Wei-ji9ou
    @Wei-ji9ou 2 ปีที่แล้ว +1

    Can malware activate without execute them ?

  • @timoteogarcia1581
    @timoteogarcia1581 4 ปีที่แล้ว

    What does MZ stand for?

  • @MayankBhardwaj-fy7ge
    @MayankBhardwaj-fy7ge ปีที่แล้ว

    😍😍😍😍😍😍

  • @cyberi2009
    @cyberi2009 4 ปีที่แล้ว

    what about Hebrew in the thanks part

  • @_nosma
    @_nosma 4 ปีที่แล้ว

    Cannot Download the sample, it gives me a 404 error page.

  • @choudhary6964
    @choudhary6964 4 ปีที่แล้ว

    Is it cryptography?

  • @pavanteja2219
    @pavanteja2219 2 ปีที่แล้ว

    The sample malware not PE right ?

  • @theunforgiven2601
    @theunforgiven2601 3 ปีที่แล้ว

    why it doesn't work for me?
    it keeps telling me that it cant open the file because if may contain viruses.
    when ever i drag the malware to the hex editor or any other program.
    please help x(
    note that it was working before, and all of sudden it didn't work again x( x(

    • @theunforgiven2601
      @theunforgiven2601 3 ปีที่แล้ว

      @Nathan Jenkins i did.. but still the malware didn't open.
      However, i used linux. And it's working :p

    • @qwerty.760
      @qwerty.760 3 ปีที่แล้ว +1

      @@theunforgiven2601 also dont run it on your main system. Use virtual box/vmware or another isolated system.

    • @theunforgiven2601
      @theunforgiven2601 3 ปีที่แล้ว

      @@qwerty.760 Yep... thank you for the advice. i used VM for that :)

    • @bobnoob1467
      @bobnoob1467 2 ปีที่แล้ว

      @@theunforgiven2601 even better, a sandbox environement.

  • @dylanzentz4525
    @dylanzentz4525 4 ปีที่แล้ว

    where can i go to find malware? i just want the source code of viruses. Where can i find them?

    • @ProfChoy
      @ProfChoy 3 ปีที่แล้ว

      Have you found them? I think GitHub has it

  • @SatyamKumar-ti6hw
    @SatyamKumar-ti6hw 4 ปีที่แล้ว

    The malware sample is no longer located in the Google drive. Error 404

    • @HackerSploit
      @HackerSploit  4 ปีที่แล้ว

      The issue should be resolved.

  • @MisterK-YT
    @MisterK-YT ปีที่แล้ว

    Windows Vista? Lol