Remnux is a Linux-based system for reverse engineering and malicious analysis.Code.
The software installed on remnux includes:
Analyze flash malware: swfttools, flasm, flare, rabcdasmand xxxswf. py
Interacting with IRC bots: IRC server (inspire ircd) and client (epic5)
Observe and interact with network activities: Wireshark, honeyd, inetsim, fakedns, fakesmtp, Netcat, networkminer, ngrep, pdnstool and tcpdump
Decode javascript: Firefox firebug, quickjava and JavaScript deobfuscator extensions, rhino debugger, js-beautify, spidermonkey, V8, Windows Script decoder and jsunpackn
Login E and interact with Web malware: Firefox tamper data and User Agent switcher extensions, tinyhttpd, burp suite Free Edition, Stunnel, Tor, jsunpackn and torsocks.
Analyze shellcode: GDB, objdump, radare, shellcode2exe, libemu's sctest
Examine suspicious executables: UPX, packerid, bytehist, densityscout, xorsearch, xortool, trid, xortools. py, ClamAV, ssdeep, md5deep, pescanner and Pyew
Analyze malicious documents: Didier Steven's PDF tools, origami framework, PDF X-RAY lite, peepdf, jsunpackn, pdftk, pyolescanner. py and hachoir
Decompile Java programs: Jad, JD-Gui
Perform memory Forensics: Volatility framework with malware, timeliner and other modules, aeskeyfinder and rsakeyfinder.
Handle miscellaneous tasks: unzip, unrar, strings, Feh Image Viewer, scite text editor, OpenSSH server, findaes, xpdf PDF viewer, vbindiff file comparison/Viewer, freemind.
See: remnux: a Linux distribution for reverse-engineering malware