Dynamic Malware Analysis
Dynamic analysis consists of running the sample in a controlled environment and observing its real behavior: what processes it creates, what it touches on disk and in the registry, what network connections it attempts, what persistence it installs. It reveals what static misses (encrypted/packed code, input-dependent logic), but it runs dangerous code, so isolation is absolute. It’s dynamic reversing (see Dynamic Analysis) applied to malware analysis.
The environment (the most important part)
Section titled “The environment (the most important part)”# dedicated VM, clean snapshot, NO access to your real network# simulated network to capture what the malware tries to contact:INetSim / FakeNet-NG fake DNS/HTTP/HTTPS/etc. -> see the C2 domains/URLs without exposure# prepared distros: REMnux (analysis) + a Windows victim VM (FLARE VM)# NOTE: much malware detects VM/sandbox and won't run (see mal-evasion)# -> "hardened" VMs to look real, or bare-metal for evasive samplesGolden rule: clean snapshot before each run, isolated/simulated network, and never the lab connected to your network or the Internet without control.
What to monitor
Section titled “What to monitor”# processes and system activity (Windows)Process Monitor (ProcMon) ALL activity: files, registry, processes, networkProcess Hacker / Explorer process tree, injections, handles, in-memory stringsAutoruns installed persistence (see mal-persist)Regshot registry/FS diff before and after# networkWireshark / tcpdump generated traffic (C2, downloads) (see net-sniffing)FakeNet/INetSim logs which domains/IPs/URLs it contacted# automated summarysandboxes: Cuckoo/CAPE, ANY.RUN, Joe Sandbox, Hybrid AnalysisCAPE/Cuckoo and online sandboxes (interactive ANY.RUN) automate all this: they run the sample and generate a behavior report + IOCs.
Behaviors to identify
Section titled “Behaviors to identify”# execution and deployment- copies itself elsewhere, renames, spawns child processes- injection into legitimate processes (explorer.exe, svchost...) -> hiding# persistence (see mal-persist)- Run keys, scheduled tasks, services, startup folders# network / C2 (see mal-c2)- domain resolution (sometimes DGA), HTTP/HTTPS/DNS beacons, 2nd-stage downloads# actions- mass file encryption (ransomware, see mal-ransomware)- credential/browser theft, keylogging- mutex (avoids double infection -> good IOC)Memory dump (unpacking and config)
Section titled “Memory dump (unpacking and config)”Malware decrypts its code/config in memory. Dumping the running process reveals what static missed:
# dump the process once unpacked/decrypted (see rev-dynamic)Process Hacker -> dump ; pe-sieve / hollows_hunter (detect injection/hollowing and dump)# analyze the dump statically (strings, capa) -> C2 config, 2nd stage# full system memory analysis:Volatility 3 (hidden processes, injections, connections) -> also in forensics (dfir)Extracting the configuration (config extraction)
Section titled “Extracting the configuration (config extraction)”# many families have the config (C2, keys, campaign) encrypted in the binary# after unpacking in memory -> extract it; there are per-family "config extractors"# tools: MWCP, CAPE config extractors, community scriptsFor the defense
Section titled “For the defense”- The observed behavior feeds Sigma rules (detection in logs/EDR) and YARA (YARA Rules) based on runtime.
- Network IOCs (C2 domains/IPs) are blocked in DNS/firewall; mutexes/artifacts are used for detection.
- Mapping behavior to MITRE ATT&CK lets you build per-technique detections, more robust than by hash.
Testing checklist
Section titled “Testing checklist”- Isolated environment with snapshot and simulated network (INetSim/FakeNet)
- Monitoring: ProcMon, Process Hacker, Regshot, Wireshark
- Run and observe: child processes, injection, files, registry
- Capture network activity (C2 domains/IPs/URLs)
- Identify persistence (Autoruns, Malware Persistence (analysis))
- Dump memory to unpack/extract config
- Volatility if system memory analysis is needed
- IOCs + behavior → detection (Sigma/YARA, MITRE)