Q:
1. What is the purpose of this malicious payload?
2. How does the malicious payload inject itself?
3. What filesystem residue does this program create?
Analyze the malware found in the file Lab12-04.exe.
1. What does the code at 0x401000 accomplish?
2. Which process has code injected?
3. What DLL is loaded using LoadLibraryA?
LoadLibraryA
4. What is the fourth argument passed to the CreateRemoteThread call?
CreateRemoteThread
5. What malware is dropped by the main executable?
6. What is the purpose of this and the dropped malware?
Войти с помощью соц. сетей: