You have been provided with an unknown file found on a suspected infected
Ask Expert

Be Prepared For The Toughest Questions

Practice Problems

You have been provided with an unknown file found on a suspected infected

Part 1: Static and dynamic analysis of an unknown suspicious file

Scenario and goal

You have been provided with an unknown file found on a suspected infected machine on your organization’s network. The goal is to perform an in-depth analysis of the file to determine its type, infection mechanisms, and document any observable behaviours. After the analysis you will recommend steps to eradicate the malware from all the other systems in your organization that have been infected by the same malware.

Answer all the questions below (in the analysis tasks section) backing your answers with appropriate proofs and detailed supporting documentation and evidence from analyses. Please provide your answers under each given question. Any references cited should be listed at the end of your report.

Environment and tools

Analyse the file “suspicious.file” on a W indows XP virtual machine. The file should be extracted from “suspicious.7z” with the archive password ‘infected’. Please note that this is real malware. Which tools you use is entirely up to you. In malware analysis there is rarely one “right” path. Be creative and observant! However, I suggest you look at previous lab exercises and lecture slides, and pick whatever tools you deem appropriate. Provide documentary evidence to support your answers where appropriate, for example screenshots, excerpts from Logs, dumps and other analyses outputs.

Analysis tasks

1. During malware analysis what steps and precautions should you take to remove the risk of infecting your own system and other systems on the network?

2. What observable features of the file suggest that it may/may not be packed? Document your observations with any applicable tools of your choice.

3. Next, perform a basic static analysis of the malware sample and document your findings. For example, what do the imports and exports tell you about the sample? (Remember, MSDN is your friend) Are there any interesting strings? Can you observe anything suspicious sectionwise? If the sample is packed, make sure you unpack it first.

4. Analyse the sample dynamically and monitor its activities on the system. What changes do you observe on the host? For example, is anything dropped, executed or deleted? (Hint: if you use Regshot in any phase of your analysis, set the right scan directory to ‘C:\’). Support your claims with documentary evidence from tools such as RegShot, Process Monitor, etc.

5. Does the malware exhibit any network-based behaviour? Analyse and document any observable network activities under (a) an isolated environment and (b) with the system connected online (in this exercise it is ok to let the sample talk to the outside world). Document all observable patterns in network activities using appropriate tools and techniques.

6. As a member of the incident response team in your organization you are tasked with the removal of the malware from all systems infected with this same malware. How would you eliminate the malware from an infected system on your network? Outline the steps to be taken in cleaning up the system. Show how you would confirm that the malware has been completely removed by the steps you have taken. (Hint: For example you can use RegShot before and after the clean-up to show that the infection has been removed).

Presentation: organization, readability, references etc.

Hint
ManagementThe in-depth analysis attempts to explain in detail a certain issue or phenomenon which does not contain the personal opinions of an author. It involves doing research carefully with great attention to details to clearly define the problem which is important to a wide audience....

Know the process

Students succeed in their courses by connecting and communicating with
an expert until they receive help on their questions

1
img

Submit Question

Post project within your desired price and deadline.

2
img

Tutor Is Assigned

A quality expert with the ability to solve your project will be assigned.

3
img

Receive Help

Check order history for updates. An email as a notification will be sent.

img
Unable to find what you’re looking for?

Consult our trusted tutors.

Developed by Versioning Solutions.