Coder Social home page Coder Social logo

alrawi / badthings-tools Goto Github PK

View Code? Open in Web Editor NEW
18.0 4.0 3.0 148 KB

This repository contains dynamic and static tools for IoT malware analysis

Home Page: https://badthings.info

YARA 72.28% Dockerfile 19.38% Shell 8.34%
binary-analysis dynamic-malware-analysis iot-malware malware-analysis malware-research security-research iot-sandbox malware-behavior malware-forensics

badthings-tools's People

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

Forkers

jk299 yof3ng

badthings-tools's Issues

DEBUG: Checking guest... ssh: connect to host 127.0.0.1 port 22: Connection timed out

(base) thematch@thematch-QiTianM650-N000:~/dynamic/bin$ sudo docker run -it --rm -v $PWD/bins:/br2/bins --privileged arm-qemu:1.0-uclibc -i /br2/bins/0a00d8f8598188451c8b23b65666ad579013ee062652a3fbc0efc75141df020d.bin -r abc.exe -t 35
2023-12-07 13:22:25 INFO: Full file path to analyze:
/br2/bins/0a00d8f8598188451c8b23b65666ad579013ee062652a3fbc0efc75141df020d.bin
2023-12-07 13:22:25 INFO: Analysis timeout: 35 sec
2023-12-07 13:22:25 INFO: Binary file renamed from 0a00d8f8598188451c8b23b65666ad579013ee062652a3fbc0efc75141df020d.bin
to abc.exe
2023-12-07 13:22:25 INFO: Running system call tracing
2023-12-07 13:22:25 INFO: Full analysis timeout disabled
2023-12-07 13:22:25 INFO: Preping rootfs for analysis
2023-12-07 13:22:25 INFO: Mounting rootfs
2023-12-07 13:22:28 INFO: Copying binary into rootfs
2023-12-07 13:22:28 INFO: Unmounting rootfs
2023-12-07 13:22:28 INFO: Starting analysis VM...
VNC server running on 127.0.0.1:5900
2023-12-07 13:22:28 INFO: Analysis VM started, waiting on guest to boot
ssh_exchange_identification: Connection closed by remote host
2023-12-07 13:22:33 DEBUG: Guest not responding, sleeping and checking later
2023-12-07 13:22:43 DEBUG: Checking guest...
ssh: connect to host 127.0.0.1 port 22: Connection timed out
2023-12-07 13:22:48 DEBUG: Guest not responding, sleeping and checking later
2023-12-07 13:22:58 DEBUG: Checking guest...
ssh: connect to host 127.0.0.1 port 22: Connection timed out
2023-12-07 13:23:03 DEBUG: Guest not responding, sleeping and checking later
2023-12-07 13:23:13 DEBUG: Checking guest...
ssh: connect to host 127.0.0.1 port 22: Connection timed out
2023-12-07 13:23:18 DEBUG: Guest not responding, sleeping and checking later

why ssh timed out?

The results of the Dynamic Analysis

Thanks for sharing the usage of docker images in details. However, the system call trace files are all empty when I analyze the binary given by the guidance (4c962e8714a622d114a6b083e5eb9b2699bff4f4f04efd669020fb2d6f158e1e). The results are shown below:
result
How to solve this problem? Thank you!

Scripts Missing

For m68k architecture, the vm start script and dockerfile are not found.

Open sourcing Dockerfiles

Would it be possible to open-source the Dockerfiles used to build the dynamic analysis images (currently hosted on Dropbox)? This would ensure reproducibility, in case Dropbox decides to take the files down for some reason, and promote open science.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.