Five years after the publication of the last release the new release of a specialized Linux distribution , designed for studying and reverse engineering malicious code. During the analysis, REMnux provides an isolated laboratory environment where one can emulate the operation of a specific targeted network service to study the behavior of malware in conditions close to reality. Another area of application for REMnux is the examination of the properties of malicious inserts on websites implemented in JavaScript.
The distribution is built on the package base of Ubuntu 18.04 and uses the LXDE desktop environment. Firefox comes as the web browser, equipped with the NoScript extension. The distribution includes a comprehensive set of tools for malware analysis, utilities for reverse engineering code, programs for studying modified malicious PDF and office documents, and tools for monitoring activity in the system. The size of REMnux, tailored for virtualization systems, amounts to 5.2 GB. In this new release, all the available tools have been updated and the composition of the distribution has been significantly expanded (the size of the virtual machine image has doubled). The list of available utilities is categorized.
Included are the following :
- Website Analysis: , , , , , , , , , , , , , ;
- Analysis of malicious Flash videos: , , , , ;
- Java Analysis: , , , , ;
- JavaScript Analysis: , , , , ;
- PDF Analysis: , , , , , , , , , , ;
- Microsoft Office Document Analysis: , , , , , , , , ;
- Shellcode Analysis: , unicode2hex-escaped, unicode2raw, , ;
- Deobfuscating obfuscated code: , , , , , , , , ,
- Extraction of string data: , , ;
- File Recovery: , , , ;
- Network Activity Monitoring: , , , ;
- Network Services: , , , , , , , accept-all-ips;
- Network Utilities: , set-static-ip, renew-dhcp, , , , ;
- Working with a collection of malware samples: , , , , ;
- Signature Detection: , , , , ;
- Scanning: , , , , , ;
- Working with hashes: , , , , , , ;
- Malware analysis for Linux: ,
- Disassemblers: , , ;
- Debuggers: , ;
- Tracing Systems: ,
- Investigate: , , , , ;
- Working with text data: , , ;
- Working with images: , ;
- Working with binary files: , ;
- Memory dump analysis: , , AESKeyFinder, RSAKeyFinder, , , ;
- Analysis of executable PE files , , , , , , , , , , , , , , , , , , ;
- Malware analysis for mobile devices: , .
Source: opennet.ru
