Question: 1 . Using dynamic analysis, determine what this malware creates. 2 . Use static techniques such as an xor search, to look for potential encoding.

1. Using dynamic analysis, determine what this malware creates.
2. Use static techniques such as an xor search, to look for potential encoding. What do you find?
3. Based on your answer to question 1, which imported function would be a good prospect for finding
the encoding functions?
4. Where is the encoding function in the disassembly?
5. Trace from the encoding function to the source of the encoded content. What is the content?
6. Can you find the algorithm used for encoding? If not, how can you decode the content?

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!