The website Any Run offers free interactive malware analysis in a sandboxed VM in the cloud. We will use this site to avoid the complications of running malware locally.
Visit Any Run and register with your university email. Once registered, follow their tutorial using the demo-sample to observe how malware executes in a sandbox. Feel free to take your time, even after the time expires you will still be able to look at the running processes and analyze HTTP Requests, Connections, DNS Requests, and Threats.
This lab focuses on Emotet, a banking trojan discovered in 2014. On the Any Run site, go to Reports β Public Submissions and search for the following MD5 hash: 0e106000b2ef3603477cb460f2fc1751. You may choose any of the many available reports. After going through the pictures, the steps below will instruct you how to recreate the analysis in Any Runβs sandbox.
If youβre stuck or the malware doesnβt behave as expected, refer to the screenshots we analyzed earlier for guidance, or try a different public report with the same MD5.