[ << ALL_FEED ]

Useful Friday post

More in Tips

Useful Friday post 🫥

During threat research, there is often an urgent need to examine a malicious file/URL/domain. In this post, we have gathered the tools we always keep at hand for quick analysis.

Online sandboxes allow you to upload a malicious file to an isolated environment and observe its activity:

https://any.run
https://www.virustotal.com
https://tria.ge
https://www.hybrid-analysis.com
https://analyze.intezer.com
https://capesandbox.com/analysis/
https://www.joesandbox.com
https://app.docguard.io/

Domain and malicious URL checking:

https://www.browserling.com/
https://urlscan.io/
https://urlhaus.abuse.ch/browse/
https://www.greynoise.io/
https://urlquery.net/
https://any.run
https://www.virustotal.com

IoT search engines scan the IPv4 space at varying frequencies and collect network information about hosts. Using these services, you can find out which services are running or which ports are open on hosts without actively interacting with them:

https://en.fofa.info/
https://search.censys.io/
https://www.zoomeye.ai/
https://www.shodan.io/
https://www.criminalip.io/
https://search.onyphe.io/
https://www.binaryedge.io/

It is important to remember that by uploading a file to such resources (especially their free versions), you are making it publicly available, where not only the service creators but also other users may interact with it.

What tools do you use for quick analysis? Share in the comments ✍🏼

#tip
@ptescalator

More from global_author

More from global_author

More in Tips