February 2012
Intermediate to advanced
800 pages
23h 55m
English
The goal of the labs for this chapter is to help you to understand the overall functionality of a program by analyzing code constructs. Each lab will guide you through discovering and analyzing a new code construct. Each lab builds on the previous one, thus creating a single, complicated piece of malware with four constructs. Once you’ve finished working through the labs, you should be able to more easily recognize these individual constructs when you encounter them in malware.
In this lab, you will analyze the malware found in the file Lab06-01.exe.
Q: | 1. What is the major code construct found in the only subroutine called by |
Q: | 2. What is the subroutine located at 0x40105F? |
Q: | 3. What is the purpose of this program? |