February 2012
Intermediate to advanced
800 pages
23h 55m
English
Analyze the malware found in the file Lab09-01.exe using OllyDbg and IDA Pro to answer the following questions. This malware was initially analyzed in the Chapter 3 labs using basic static and dynamic analysis techniques.
Q: | 1. How can you get this malware to install itself? |
Q: | 2. What are the command-line options for this program? What is the password requirement? |
Q: | 3. How can you use OllyDbg to permanently patch this malware, so that it doesn’t require the special command-line password? |
Q: | 4. What are the host-based indicators of this malware? |
Q: | 5. What are the different actions this malware can be instructed to take via the network? |
Q: | 6. Are there any useful network-based signatures for this malware? |
Analyze the malware found ...