February 2012
Intermediate to advanced
800 pages
23h 55m
English
Analyze the malware found in the file Lab13-01.exe.
Q: | 1. Compare the strings in the malware (from the output of the |
Q: | 2. Use IDA Pro to look for potential encoding by searching for the string |
Q: | 3. What is the key used for encoding and what content does it encode? |
Q: | 4. Use the static tools FindCrypt2, Krypto ANALyzer (KANAL), and the IDA Entropy Plugin to identify any other encoding mechanisms. What do you find? |
Q: | 5. What type of encoding is used for a portion of the network traffic sent by the malware? |
Q: | 6. Where is the Base64 function in the disassembly? |
Q: | 7. What ... |