PeStudio
A good place to begin a static analysis of a single file is with PeStudio. Chapter 8, Analyzing System Memory, introduced this application when examining suspect malicious software obtained through the analysis of a memory image. In this case, an actual piece of malware will be analyzed, using PeStudio. This tool allows analysts to focus on specific attributes of the malware, for further analysis.
In this scenario, a live piece of malware will be examined. The malware sample is an Emotet infection with TrickBot. This sample was taken from https://www.malware-traffic-analysis.net/2019/09/18/index.html. Ensure that the proper preconfiguration is completed prior to downloading any malware, as any anti-virus program will quarantine ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access