Question: Task 3 Disassemble. ( postpone Task 3 to week 7 ) 1 . Disassemble lab 4 . exe with IDA and GHIDRA 2 . Does
Task Disassemble. postpone Task to week
Disassemble labexe with IDA and GHIDRA
Does the disassemblers analysis determine a main subroutine? Where is it
Hint: Use Ghidra and locate the entry function. Then use the decompile window to
confirm the main function. Note that the main function is in text section
In IDA, use the Strings window to find the Magic bytes string and then the bytes
that get appended to the string before being printed out.
In GHIDRA, use the Defined Strings window to find the Magic bytes string and
then the bytes that get appended to the string before being printed out.
What is the purpose of this malware?
Hint: Search for readable strings and for youtube links. You can also use Process
Monitor and check events. This should help you understand what the malware is trying to
do
Is there anything that this malware does that could be used as a fingerprint to find it on
other systems?
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
