Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 12th, 2010, 11:00 GMT · By

Reverse Engineer Releases Linux Distro for Malware Research

SHARE:

Adjust text size:


REMnux Linux distro packs flurry of malware analysis tools
Enlarge picture
A reputed security expert named Lenny Zeltser, who specializes in reverse-engineering malicious software has put together a special Linux distribution tailored to the specific needs of malware researchers. Called REMnux, the distro contains a wide variety of tools for analyzing malicious traffic and inspecting various threats.

According to Lenny Zeltser, who teaches the Reverse-Engineering Malware (REM) course at SANS Institute, REMnux does not aim to be the ultimate malware analysis tool collection, because most such applications work only on Windows anyway. However, this Ubuntu-based distro can be useful for someone getting started into the field.

The included network-monitoring tools like Wireshark, Honeyd, INetSim or netcat can be used to intercept and analyze traffic sent by an infected computer. This can allow a researcher to see what kind of data a piece of malware collects, what instructions it sends back to the command and control server or what Internet-related actions it performs.

As far as actual malware sample analysis in concerned, the distro comes with tools for analyzing a variety of threats, from obfuscated JavaScript code, to malformed PDFs, malicious SWF files to Windows executables. Firebug, NoScript, Jsunpack-n, are just of the few programs included that can be used to inspect JavaScript code.

Applications like upx, xorsearch, TriD, packerid, objdump, Radare, gdb, are useful at analyzing executables and shellcode. Didier Steven's PDF tools, as well as pdftk, the Origami framework can be used to investigate suspicious PDF documents, while swftools, flasm and flare are for inspecting SWFs. The distro also comes with memory forensics tools like the Volatility Framework and also contains the programs needed to analyze IRC bots.

REMnux is currently distributed as a virtual machine, which can be started with VMware Player. It uses Enlightenment as window manager instead of GNOME or KDE and has to be manually started after logging in.

“REMnux isn't a fancy distribution that was built from scratch... In simple terms, it's a virtual machine that runs Ubuntu and has various useful malware tools set up on it. REMnux is designed for running services that are useful to emulate within an isolated laboratory environment when performing behavioral malware analysis,” Lenny Zeltser, concludes.

REMnux can be downloaded from here.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,449 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Technology to Defend Against Flash-Based Attacks

WeakNet IV Linux, a Great Distro for Security Experts

PDF /Launch Trick Spotted in New Attack

Revamped MBR Rootkit Impresses Security Researchers

Interesting Anti-Emulation Programming Trick in Fake AVs

READER COMMENTS:


Comment #1 by: Paul on 13 Jul 2010, 03:50 UTC reply to this comment

REMnux and Ubuntu is the answer for solutions even for malware meant for windows!

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM