Skip to content

Dynamic Malware Analysis

Dynamic analysis consists of running the sample in a controlled environment and observing its real behavior: what processes it creates, what it touches on disk and in the registry, what network connections it attempts, what persistence it installs. It reveals what static misses (encrypted/packed code, input-dependent logic), but it runs dangerous code, so isolation is absolute. It’s dynamic reversing (see Dynamic Analysis) applied to malware analysis.

# dedicated VM, clean snapshot, NO access to your real network
# simulated network to capture what the malware tries to contact:
INetSim / FakeNet-NG fake DNS/HTTP/HTTPS/etc. -> see the C2 domains/URLs without exposure
# prepared distros: REMnux (analysis) + a Windows victim VM (FLARE VM)
# NOTE: much malware detects VM/sandbox and won't run (see mal-evasion)
# -> "hardened" VMs to look real, or bare-metal for evasive samples

Golden rule: clean snapshot before each run, isolated/simulated network, and never the lab connected to your network or the Internet without control.

# processes and system activity (Windows)
Process Monitor (ProcMon) ALL activity: files, registry, processes, network
Process Hacker / Explorer process tree, injections, handles, in-memory strings
Autoruns installed persistence (see mal-persist)
Regshot registry/FS diff before and after
# network
Wireshark / tcpdump generated traffic (C2, downloads) (see net-sniffing)
FakeNet/INetSim logs which domains/IPs/URLs it contacted
# automated summary
sandboxes: Cuckoo/CAPE, ANY.RUN, Joe Sandbox, Hybrid Analysis

CAPE/Cuckoo and online sandboxes (interactive ANY.RUN) automate all this: they run the sample and generate a behavior report + IOCs.

# execution and deployment
- copies itself elsewhere, renames, spawns child processes
- injection into legitimate processes (explorer.exe, svchost...) -> hiding
# persistence (see mal-persist)
- Run keys, scheduled tasks, services, startup folders
# network / C2 (see mal-c2)
- domain resolution (sometimes DGA), HTTP/HTTPS/DNS beacons, 2nd-stage downloads
# actions
- mass file encryption (ransomware, see mal-ransomware)
- credential/browser theft, keylogging
- mutex (avoids double infection -> good IOC)

Malware decrypts its code/config in memory. Dumping the running process reveals what static missed:

# dump the process once unpacked/decrypted (see rev-dynamic)
Process Hacker -> dump ; pe-sieve / hollows_hunter (detect injection/hollowing and dump)
# analyze the dump statically (strings, capa) -> C2 config, 2nd stage
# full system memory analysis:
Volatility 3 (hidden processes, injections, connections) -> also in forensics (dfir)

Extracting the configuration (config extraction)

Section titled “Extracting the configuration (config extraction)”
# many families have the config (C2, keys, campaign) encrypted in the binary
# after unpacking in memory -> extract it; there are per-family "config extractors"
# tools: MWCP, CAPE config extractors, community scripts
  • The observed behavior feeds Sigma rules (detection in logs/EDR) and YARA (YARA Rules) based on runtime.
  • Network IOCs (C2 domains/IPs) are blocked in DNS/firewall; mutexes/artifacts are used for detection.
  • Mapping behavior to MITRE ATT&CK lets you build per-technique detections, more robust than by hash.
  • Isolated environment with snapshot and simulated network (INetSim/FakeNet)
  • Monitoring: ProcMon, Process Hacker, Regshot, Wireshark
  • Run and observe: child processes, injection, files, registry
  • Capture network activity (C2 domains/IPs/URLs)
  • Identify persistence (Autoruns, Malware Persistence (analysis))
  • Dump memory to unpack/extract config
  • Volatility if system memory analysis is needed
  • IOCs + behavior → detection (Sigma/YARA, MITRE)