Malware › Module 2 › Lesson 4
Lab — Families
Pack malware families literacy — trojan/worm/virus, ransomware defender view, spyware/APT — literacy file only, dest $MAL_LAB.
Visual · mal_families_lab
Lab: write families pack. $MAL_LAB only. Original Cyberlium.
Opening
Families pack before sample labels — taxonomy on paper first.
Lessons 2-1 through 2-3 covered trojan/worm/virus, ransomware defender view, and spyware/APT naming. This lab merges them into one families literacy pack for $MAL_LAB report templates. No live sample required — classification vocabulary first. Next: Quiz — Malware Families Literacy.
1. Lab contract: write the families pack
Create $HOME/cyberlium-lab/t22-m02-l04-families-lab.txt merging family table, ransomware defender checklist, spyware/APT note, and NEVER authorship/encryption lines.
Optional: label one legal training sample hash with best-fit family category — static metadata only.
Command guide
Try these commands — Lab contract: write the families pack
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
CISA ransomware resources — https://www.cisa.gov/stopransomware (incident response) VirusTotal intelligence — https://www.virustotal.com/ (family naming literacy) Microsoft threat names — https://learn.microsoft.com/en-us/defender-endpoint/malware-naming
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install curl sudo apt install python3
macOS:
Command — copy this
brew install python3
Windows: Built-in (PowerShell: Invoke-WebRequest) Download https://python.org/downloads/
═══ LINUX / macOS ═══
Command — copy this
source "$HOME/cyberlium-lab/t22-mal/lab.env" 2>/dev/null || true
python3 <<'PY'
notes = {'Emotet': 'loader/dropper', 'Ryuk': 'ransomware', 'defender': 'CISA guidance + backups'}
for k, v in notes.items(): print(f'{k}: {v}')
PYCommand — copy this
grep -h . "$HOME/cyberlium-lab/t22-mal/notes/families.txt" | head -5 curl -sS https://www.cisa.gov/stopransomware | head -5
Primary tools to practice this lesson: grep, curl, python3. Reference sites: CISA ransomware resources (https://www.cisa.gov/stopransomware); VirusTotal intelligence (https://www.virustotal.com/); Microsoft threat names (https://learn.microsoft.com/en-us/defender-endpoint/malware-naming). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Cross-check weaponization language
Grep pack for builder links, encrypt loops, keylogger steps — delete. Tutorials showing ransomware construction get rewritten to defender detection notes only.
Classmates write their own families packs for their $MAL_LAB.
3. Lock the proof
chmod 600 on the pack. Quiz next — then Static Analysis Basics.
Family labels feed static triage in Module 3.
4. What you ship: malware families literacy pack for $MAL_LAB
Family table + ransomware defender checklist + spyware/APT note merged. $MAL_LAB named. No builders. chmod 600.
5. What you record before the next lesson
Date. Families pack path. $MAL_LAB named. File t22-m02-l04-families-lab.txt chmod 600.
6. Wrong vs right: live malware on daily driver vs sandbox
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Add ransomware builder URL to pack. Include keylogger tutorial steps.
Right
Write YOUR families literacy pack for $MAL_LAB. chmod 600. Next: Quiz — Malware Families Literacy.
Mission: freeze YOUR families pack on disk
1) Merge all M2 literacy sections. 2) Name $MAL_LAB. 3) chmod 600. Never include encryption or spyware deployment steps.
Stuck? Ask Cyberlium AI Mentor
Taxonomy packs make reports consistent — keep them defender-focused.
Knowledge Check
APPLY: This lab requires:
Multiple choice
Knowledge Check
APPLY: True or False: Families pack should include NEVER encryption how-to line.
True or False
Knowledge Check
APPLY: Ransomware section belongs in pack as:
Multiple choice