February 2012
Intermediate to advanced
800 pages
23h 55m
English
Analyze the malware found in the file Lab03-01.exe using basic dynamic analysis tools.
Q: | 1. What are this malware’s imports and strings? |
Q: | 2. What are the malware’s host-based indicators? |
Q: | 3. Are there any useful network-based signatures for this malware? If so, what are they? |
Analyze the malware found in the file Lab03-02.dll using basic dynamic analysis tools.
Q: | 1. How can you get this malware to install itself? |
Q: | 2. How would you get this malware to run after installation? |
Q: | 3. How can you find the process under which this malware is running? |
Q: | 4. Which filters could you set in order to use procmon to glean information? |
Q: | 5. What are the malware’s host-based indicators? |
Q: | 6. Are there any useful network-based signatures ... |