August 2019
Intermediate to advanced
342 pages
9h 35m
English
Among the most insidious aspects of static malware analysis are the difficulties in determining the correctness of the malware disassembly. Given the increasingly widespread presence of anti-analysis techniques, it is not always possible to assume that the disassembled binary image produced by the disassembler is reliable. Therefore, the analyst must conduct a preliminary analysis, in order to detect, for example, the presence of packers that encrypt portions of executable code.
Such preliminary analysis procedures are often overlooked by analysts because they are expensive in terms of time required; nevertheless, they are indispensable for circumscribing relevant goals to be carried out.
In addition, ...
Read now
Unlock full access