Книга: Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
Назад: Identifying Packed Programs
Дальше: Automated Unpacking

There are three options for unpacking a packed executable: automated static unpacking, automated dynamic unpacking, and manual dynamic unpacking. The automated unpacking techniques are faster and easier than manual dynamic unpacking, but automated techniques don’t always work. If you have identified the kind of packer used, you should determine if an automated unpacker is available. If not, you may be able to find information about how to unpack the packer manually.

When dealing with packed malware, remember that your goal is to analyze the behavior of the malware, which does not always require you to re-create the original malware. Most of the time, when you unpack malware, you create a new binary that is not identical to the original, but does all the same things as the original.

Назад: Identifying Packed Programs
Дальше: Automated Unpacking

sss
sss