We do a deep analysis of a suspicious file

Teacher

Professional
Messages
2,677
Reputation
9
Reaction score
632
Points
113
Deep file scan for viruses!
The article is of an educational nature, we do not call for anything or oblige. The information is presented for informational purposes only.

Introduction
Hello everyone, everyone who downloaded cheats / programs / other software thought: "Is there a virus in the program?" Of course, they can be, every day who climbs sites with software may come across similar programs containing malicious code that will be a miner / clipper / ransomware or ransomware (almost the same thing), and so, for those who are afraid to download software from the Internet and is afraid for his confidential information, then this article is for you, so that you do a deep analysis and make sure the file is clean. Since not everyone can parse the file into code and see what it contains, because basically - the program code is closed.

Start
Sites that we will use to parse the file:
1) app.any.run
2) hybrid-analysis.com
3) opentip.kaspersky.com
4) virustotal.com
5) vms.drweb.ru/scan_file/

For example, we will use the AIO (Checker), the crack of which was merged into the lolza. (I am not responsible if you run it on your main machine and something happens to it)

1) Download our file

yxX2AFk.png


2) We get our file from the archive:

IbNk874.png


3) First you need to find out if the file itself contains malicious code, so upload it to https://virustotal.com

JL28lKB.png


It's funny, but at this point, many users have already given up the download, but we will write off everything to "KRYAK".

4) After receiving the result, we go to app.any.run and check if the file itself is working.

Firstly, you need to register on it, there is nothing complicated there, so I will not explain how to do this.

After registration, click here:

eJcKylx.png


Next, we poke here, after opening the menu:

WlMXti0.png


We should have a menu like this:

sTuBCBp.png


Click Upload and upload our file, which we are examining. Further, as we can see, the checker is loaded:

Z4kDcuC.png


Now I am showing the optimal settings that you set, everything should be like this:

U3PQhHJ.png


Click Run a public test:

RlrTljC.png


Agree and wait for the download. Next, your file automatically opens and you see what it does:

H4ooqlS.png

eFbQI9l.png


If the program is stable and there are no icons that appear next to the program name, for example: stealer / trojan / redline and also, the file is not marked as red, then the file passed the app.any.run test by 100 percent. Also, look at what the file did on the virtual pc, just right-click on it and this will come out:

UZXD5Lv.png


5) Okay, there was no malicious activity, so we continue the analysis. If app.any.run found something, then there is a virus and it is pointless to continue the analysis. Here's an example from app.any.run that shows the redline styler at work:

JfZJP9H.png


6) Next, we go to the site https://www.hybrid-analysis.com and load our file:

8PSj602.png


After downloading the file, we will get out a menu, which we fill in and press Continue

HMdKFA0.png


You can put any mail, we don't need it. Next, such a menu will pop up (be sure to select everything as in the screenshot):

MEtPtOd.png


Next, go to Runtime Options and select everything again like me:

lQhohyT.png


Then press Generate Public Report and wait for the result, and then study it:

UhnyEtQ.png


As we can see, it fails the test and gets 100/100.

Next, we go to the site https://opentip.kaspersky.com, and upload our file there. After loading, click Analyze:

iyUZ8Dr.png


We are waiting for the download:

UHk2IpJ.png


Strange, but the program passes the test from Kaspersky:

H20WMVZ.png


Now we are waiting for a deeper analysis from them:

jNWc5TP.png


As we can see, the program did not do any harmful actions, which can be seen from the panel also on app.any.run:

C4EtqFN.png


5) And the last step, we pour our experimental on the site https://vms.drweb.ru/scan_file, or scan it with any other antivirus and get the following result:

tv8OJ8c.png


Next, we collect and consider all the information about this file, the analyzes that we received. Most likely, the antivirus complains about a crack, but it can, of course, also have malware embedded in it. And we conclude: it is better to run it on a virtual machine, or a RDP (Dedicated Server) one.

0q9mCds.png

5uEPooT.png


That's all! Good luck!
 
Top