PE

performing-dynamic-analysis-with-any-run

Analyzes malware interactively using the ANY.RUN cloud sandbox to observe real-time behavior and process activity.

Install

mkdir -p .claude/skills/performing-dynamic-analysis-with-any-run && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/16730" && unzip -o skill.zip -d .claude/skills/performing-dynamic-analysis-with-any-run && rm skill.zip

Installs to .claude/skills/performing-dynamic-analysis-with-any-run

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Performs interactive dynamic malware analysis using the ANY.RUN cloud
69 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Interact with malware during execution
  • Analyze process trees
  • Review network activity
  • Examine Indicators of Compromise (IOCs)
  • Configure analysis environment
  • Share analysis results

How it works

The skill configures an ANY.RUN task with parameters like OS selection and execution time, then allows interactive actions with the malware. It analyzes the process execution chain, network traffic, and extracts indicators of compromise.

Inputs & outputs

You give it
A suspicious sample file (e.g., invoice_q3.docm)
You get back
An ANY.RUN analysis report with verdict, process tree, network indicators, and MITRE ATT&CK techniques

When to use performing-dynamic-analysis-with-any-run

  • Analyzing malware behavior
  • Testing malicious macros
  • Observing process trees in malware

About this skill

Performing Dynamic Analysis with ANY.RUN

When to Use

  • Interactive malware analysis is needed where the analyst must click dialogs, enter credentials, or navigate installer screens
  • Rapid cloud-based sandbox analysis without maintaining local sandbox infrastructure
  • Malware requires user interaction to proceed past anti-sandbox checks (document macros requiring "Enable Content")
  • Sharing analysis results with team members via public or private task URLs
  • Comparing behavior across different OS versions (Windows 7, 10, 11) available in ANY.RUN

Do not use for highly sensitive samples that cannot be uploaded to cloud services; use an on-premises sandbox like Cuckoo instead.

Prerequisites

  • ANY.RUN account (free community tier or paid subscription at https://any.run)
  • Modern web browser with WebSocket support for interactive session streaming
  • Sample file ready for upload (max 100 MB for free tier, 256 MB for paid)
  • Understanding of the sample type to select appropriate execution environment
  • VPN or secure network for accessing ANY.RUN portal during analysis sessions

Workflow

Step 1: Configure Analysis Environment

Set up the ANY.RUN task with appropriate parameters:

ANY.RUN Task Configuration:
━━━━━━━━━━━━━━━━━━━━━━━━━━
OS Selection:        Windows 10 x64 (recommended default)
                     Windows 7 x64 (for legacy malware)
                     Windows 11 x64 (for modern samples)
Execution Time:      60 seconds (default) / 120-300 for slow-acting malware
Network:             Connected (captures real C2 traffic)
                     Residential Proxy (bypasses geo-blocking)
Privacy:             Public (free tier) / Private (paid - not indexed)
MITM Proxy:          Enable for HTTPS traffic decryption
Fake Net:            Enable to simulate internet services if sample checks connectivity

API-based submission (paid tier):

# Submit file via ANY.RUN API
curl -X POST "https://api.any.run/v1/analysis" \
  -H "Authorization: API-Key $ANYRUN_API_KEY" \
  -F "[email protected]" \
  -F "env_os=windows" \
  -F "env_version=10" \
  -F "env_bitness=64" \
  -F "opt_timeout=120" \
  -F "opt_network_connect=true" \
  -F "opt_privacy_type=bylink"

# Check task status
curl "https://api.any.run/v1/analysis/$TASK_ID" \
  -H "Authorization: API-Key $ANYRUN_API_KEY" | jq '.data.status'

Step 2: Interact with Malware During Execution

Use the interactive session to trigger malware behavior:

Interactive Actions During Analysis:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. Document Macros:   Click "Enable Content" / "Enable Editing" when prompted
2. Installer Screens: Click through installation dialogs
3. UAC Prompts:       Click "Yes" to allow elevation (observe privilege escalation)
4. Credential Harvests: Enter fake credentials to observe phishing behavior
5. Browser Redirects:  Navigate to URLs if malware opens browser windows
6. File Dialogs:       Select target files if malware presents file picker
7. Timeout Extension:  Extend analysis time if malware has delayed execution

Step 3: Analyze Process Tree

Review the complete process execution chain:

Process Tree Analysis Points:
━━━━━━━━━━━━━━━━━━━━━━━━━━━
Parent-Child Relationships:
  - WINWORD.EXE -> cmd.exe -> powershell.exe (macro execution chain)
  - explorer.exe -> suspect.exe -> svchost.exe (process injection)

Process Events to Note:
  - Process creation with suspicious command-line arguments
  - PowerShell with encoded commands (-enc / -encodedcommand)
  - cmd.exe executing script files (.bat, .vbs, .js)
  - Legitimate processes spawned from unusual parents
  - Process termination (self-deletion behavior)

Step 4: Review Network Activity

Examine DNS, HTTP/HTTPS, and TCP/UDP connections:

ANY.RUN Network Panel Analysis:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DNS Requests:
  - Domain resolutions with threat intelligence tags
  - Fast-flux or DGA domain patterns
  - DNS over HTTPS (DoH) detection

HTTP/HTTPS Traffic (with MITM enabled):
  - Full request/response bodies for HTTP
  - Decrypted HTTPS traffic showing C2 commands
  - Downloaded payloads and their content types
  - POST data containing exfiltrated information

Connection Map:
  - Geographic visualization of C2 server locations
  - Connection timeline showing beacon patterns
  - Suricata alerts triggered on network traffic

Step 5: Examine IOCs and Threat Intelligence

Extract indicators and map to known threats:

ANY.RUN IOC Categories:
━━━━━━━━━━━━━━━━━━━━━━
Files:       Dropped files with hashes, YARA matches, VirusTotal results
Network:     IPs, domains, URLs contacted during execution
Registry:    Keys created/modified for persistence
Processes:   Suspicious process names and command lines
Mutex:       Named mutexes created (used for single-instance checking)
Signatures:  Suricata rules triggered, behavioral signatures matched

MITRE ATT&CK Mapping:
  - ANY.RUN automatically maps observed behaviors to ATT&CK techniques
  - Review the ATT&CK matrix tab for technique coverage
  - Export ATT&CK Navigator layer for reporting

Step 6: Export Analysis Results

Download comprehensive reports and artifacts:

# Download report via API
curl "https://api.any.run/v1/analysis/$TASK_ID/report" \
  -H "Authorization: API-Key $ANYRUN_API_KEY" \
  -o report.json

# Download PCAP
curl "https://api.any.run/v1/analysis/$TASK_ID/pcap" \
  -H "Authorization: API-Key $ANYRUN_API_KEY" \
  -o capture.pcap

# Download dropped files
curl "https://api.any.run/v1/analysis/$TASK_ID/files" \
  -H "Authorization: API-Key $ANYRUN_API_KEY" \
  -o dropped_files.zip

# Available exports from ANY.RUN web interface:
# - HTML Report (shareable standalone page)
# - PCAP file (network traffic capture)
# - Process dump (memory dumps of processes)
# - Dropped files (all files created during execution)
# - MITRE ATT&CK Navigator JSON
# - IOC export (STIX/JSON/CSV format)

Key Concepts

TermDefinition
Interactive SandboxAnalysis environment allowing real-time analyst interaction with the executing sample, enabling triggering of user-dependent behaviors
MITM ProxyMan-in-the-middle TLS interception in ANY.RUN that decrypts HTTPS traffic for visibility into encrypted C2 communications
Residential ProxyANY.RUN feature routing malware traffic through residential IP addresses to bypass geo-IP and datacenter-IP evasion checks
Suricata AlertsNetwork IDS signatures triggered during execution, providing immediate identification of known malicious traffic patterns
Process TreeHierarchical visualization of parent-child process relationships showing the complete execution chain from initial sample to final payloads
Behavioral TagsANY.RUN classification labels automatically applied based on observed behavior (e.g., "trojan", "stealer", "ransomware")

Tools & Systems

  • ANY.RUN: Cloud-based interactive malware sandbox providing real-time execution monitoring, process trees, network capture, and MITRE ATT&CK mapping
  • ANY.RUN API: REST API for programmatic sample submission, status checking, and report/artifact retrieval
  • Suricata: Integrated network IDS within ANY.RUN providing signature-based detection of malicious network traffic
  • MITRE ATT&CK Navigator: Framework integration mapping observed malware behaviors to adversary techniques and tactics
  • VirusTotal Integration: Automatic hash lookup of sample and dropped files against VirusTotal detection results

Common Scenarios

Scenario: Analyzing a Macro-Enabled Document Requiring User Interaction

Context: Phishing email contains a .docm file that requires clicking "Enable Content" to trigger the macro payload. Traditional non-interactive sandboxes fail to trigger the malicious behavior.

Approach:

  1. Upload .docm to ANY.RUN with Windows 10 environment and Microsoft Office installed
  2. When Word opens and displays the security banner, click "Enable Content" interactively
  3. Observe the macro execution in the process tree (Word -> cmd.exe -> powershell.exe)
  4. Monitor network panel for PowerShell downloading second-stage payload
  5. If a UAC prompt appears, click "Yes" to allow the payload to observe full behavior chain
  6. Review Suricata alerts for known malware signatures on the downloaded payload
  7. Export IOCs (download URLs, dropped file hashes, C2 domains) for blocking

Pitfalls:

  • Forgetting to enable MITM proxy, resulting in encrypted HTTPS traffic without visibility
  • Using too short an execution timeout for malware with delayed execution or sleep timers
  • Uploading to public analysis when the sample contains sensitive organizational data
  • Not clicking through all prompts; some malware requires multiple user interactions to fully execute

Output Format

ANY.RUN ANALYSIS REPORT
=========================
Task URL:         https://app.any.run/tasks/<task_id>
Sample:           invoice_q3.docm
SHA-256:          e3b0c44298fc1c149afbf4c8996fb924...
Verdict:          MALICIOUS (Score: 95/100)
Family:           Emotet
Tags:             [trojan, banker, spam, macro]

PROCESS TREE
WINWORD.EXE (PID: 2184)
  └── cmd.exe (PID: 3456) "/c powershell -enc JABXAG..."
      └── powershell.exe (PID: 4012)
          └── rundll32.exe (PID: 4568) "C:\Users\...\payload.dll,Control_RunDLL"

NETWORK INDICATORS
DNS:    update.emotet-c2[.]com -> 185.220.101.42
HTTPS:  POST hxxps://185.220.101[.]42/wp-content/gate/ (C2 beacon)
HTTP:   GET hxxp://compromised-site[.]com/invoice.dll (payload download)

SURICATA ALERTS
[1:2028401] ET MALWARE Emotet CnC Beacon
[1:2028402] ET MALWARE Win32/Emotet Activity

MITRE ATT&CK TECHNIQUES
T1566.001  Phishing: Spearphishing Attachment
T1204.002  User Execution: Malicious File
T1059.001  Command and Scripting Interpreter: PowerShell
T1218.011  Rundll32 Execution
T1071.001  Application Layer Protocol: Web Protocols

DROPPED FILES
payload.dll  SHA

---

*Content truncated.*

When not to use it

  • When samples are highly sensitive and cannot be uploaded to cloud services

Prerequisites

ANY.RUN accountModern web browser with WebSocket supportSample file ready for uploadUnderstanding of the sample type

Limitations

  • Maximum sample size for free tier is 100 MB
  • Public analysis for free tier samples
  • Requires user interaction for some malware to fully execute

How it compares

This skill provides an interactive cloud-based sandbox for malware analysis, unlike manual methods that require local infrastructure and may lack real-time interaction features.

Compared to similar skills

performing-dynamic-analysis-with-any-run side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
performing-dynamic-analysis-with-any-run (this skill)01moReviewIntermediate
reverse-engineering-tools734moNo flagsAdvanced
ghidra167moReviewAdvanced
firmware-analyst94moReviewAdvanced

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

firmware-analyst

sickn33

Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.

947

memory-forensics

wshobson

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from RAM captures.

748

binary-analysis-patterns

wshobson

Master binary analysis patterns including disassembly, decompilation, control flow analysis, and code pattern recognition. Use when analyzing executables, understanding compiled code, or performing static analysis on binaries.

540

security-scanning-tools

davila7

This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detect malware", "check cloud security", or "evaluate system compliance". It provides comprehensive guidance on security scanning tools and methodologies.

438

Search skills

Search the agent skills registry