Release of REMnux 8.0, a distribution for malware analysis

The release of the specialized Linux distribution REMnux 8.0 is designed for studying and reverse engineering malware code. REMnux allows creating an isolated lab environment to emulate the operation of targeted network services to study the behavior of malware under conditions close to reality.

This distribution is built on the Ubuntu package base and includes tools for malware analysis, utilities for reverse engineering code, programs for examining modified PDFs and office documents by attackers, as well as monitoring tools for system activity. It offers over 200 specialized tools. Available for download are images for virtualization systems in 'ova' (VirtualBox) and 'bqcow2' (Proxmox) formats, with a size of 8 GB. The project also distributes a set of Docker images for the isolated execution of individual tools in existing systems.

In the new version:

  • The system environment has been updated from Ubuntu 20.04 to 24.04. The versions of the tools included in the distribution have been updated.
  • A new installer has been added that allows the installation of the distribution environment on top of existing Ubuntu 24.04 installations.
  • Support for AI assistants for malware analysis has been provided. It includes its own MCP server for integrating the tools available in the distribution with various AI agents. The AI agent OpenCode can now be used in the terminal. The GhidrAssistMCP package has been added to automate reverse engineering in the Ghidra package. Plugins r2ai and decai for the Radare2 framework have been introduced.
  • New tools have been included, among them:
    • YARA-X (YARA rewritten in Rust) with updated YARA-Forge rules.
    • GoReSym and Redress for analyzing executable files from Go projects.
    • Manalyze and LIEF for parsing executable files in PE/ELF/MachO formats.
    • pyinstxtractor-ng, uncompyle6, and AutoIt-Ripper for analyzing malware in Python.
    • APKiD for analyzing Android applications.
    • origamindee for parsing PDFs.
    • zbar-tools for decoding QR codes.

Among the included tools are:

  • Website analysis: Thug, mitmproxy, Network Miner Free Edition, curl, Wget, Burp Proxy Free Edition, Automater, pdnstool, Tor, tcpextract, tcpflow, passive.py, CapTipper, yaraPcap.py;
  • Analysis of malicious Flash files: xxxswf, SWF Tools, RABCDAsm, extract_swf, Flare;
  • Java Analysis: Java Cache IDX Parser, JD-GUI Java Decompiler, JAD Java Decompiler, Javassist, CFR;
  • JavaScript Analysis: Rhino Debugger, ExtractScripts, SpiderMonkey, V8, JS Beautifier;
  • PDF Analysis: AnalyzePDF, Pdfobjflow, pdfid, pdf-parser, peepdf, Origami, PDF X-RAY Lite, PDFtk, swf_mastah, qpdf, pdfresurrect;
  • Microsoft Office Document Analysis: officeparser, pyOLEScanner.py, oletools, libolecf, oledump, emldump, MSGConvert, base64dump.py, unicode;
  • Shellcode Analysis: sctest, unicode2hex-escaped, unicode2raw, dism-this, shellcode2exe;
  • Deobfuscating obfuscated code: unXOR, XORStrings, ex_pe_xor, XORSearch, brxor.py, xortool, NoMoreXOR, XORBruteForcer, Balbuzard, FLOSS
  • String data extraction: strdeobj, pestr, strings;
  • File recovery: Foremost, Scalpel, bulk_extractor, Hachoir;
  • Network activity monitoring: Wireshark, ngrep, TCPDump, tcpick;
  • Network services: FakeDNS, Nginx, fakeMail, Honeyd, INetSim, Inspire IRCd, OpenSSH, accept-all-ips;
  • Network utilities: prettyping.sh, set-static-ip, renew-dhcp, Netcat, EPIC IRC Client, stunnel, Just-Metadata;
  • Working with a collection of malware samples: Maltrieve, Ragpicker, Viper, MASTIFF, Density Scout;
  • Signature determination: YaraGenerator, IOCextractor, Autorule, Rule Editor, ioc-parser;
  • Scanning: Yara, ClamAV, TrID, ExifTool, virustotal-submit, Disitool;
  • Working with hashes: nsrllookup, Automater, Hash Identifier, totalhash, ssdeep, virustotal-search, VirusTotalApi;
  • Malware analysis for Linux: Sysdig, Unhide
  • Disassemblers: Vivisect, Udis86, objdump;
  • Debuggers: Evan’s Debugger (EDB), GNU Project Debugger (GDB);
  • Tracing systems: strace, ltrace
  • Investigate: Radare 2, Pyew, Bokken, m2elf, ELF Parser;
  • Working with text data: SciTE, Geany, Vim;
  • Working with images: feh, ImageMagick;
  • Working with binary files: wxHexEditor, VBinDiff;
  • Memory dump analysis: Volatility Framework, findaes, AESKeyFinder, RSAKeyFinder, VolDiff, Rekall, linux_mem_diff_tool;
  • Analysis of executable PE files: UPX, Bytehist, Density Scout, PackerID, objdump, Udis86, Vivisect, Signsrch, pescanner, ExeScan, pev, Peframe, pedump, Bokken, RATDecoders, Pyew, readpe.py, PyInstaller Extractor, DC3-MWCP;
  • Mobile malware analysis: Androwarn, AndroGuard.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster