当前位置:网站首页>Malicious code analysis practice - lab03-01 Exe basic dynamic analysis
Malicious code analysis practice - lab03-01 Exe basic dynamic analysis
2022-06-12 10:33:00 【Bng!】
Malicious code analysis practice ——Lab03-01.exe Basic dynamic analysis
1. The experiment purpose
Comprehensive use of various analytical tools , analysis Lab03-01.exe Basic information of , And speculate its function .
2. Experimental environment ( Hardware 、 Software )
VMware virtual machine (winxp):
Hardware : processor Intel Core i5-10210U CPU @ 1.60GHz 2.11 GHz
Software :32 Bit operating system
kali virtual machine
3. The experimental steps ( Describe the operation process in detail , The key analysis needs to be attached with screenshots )
(1) Static analysis
①MD5 value

②peid analysis

You can see Lab03-01.exe Has been shelled
③strings analysis
strings Lab03-01.exe


Found some registry information and a exe File and a possible domain name
Guess analysis may visit the website to download some Trojan files through the connection, or through vmx32to64.exe Download open some back doors ,, Therefore, the dynamic analysis focuses on the addition and deletion of registry modification information and files, as well as networking operations
(2) dynamic analysis
①regshot Registry analysis
Regshot Run after the first snapshot Lab03-01.exe
function Lab03-01.exe Record the second snapshot after 
Click on compare After comparing the registry information twice, it is found that the new registry key value 
Found in the self start item VideoDriver Key value is added in 43 3A 5C 57 49 4E 44 4F 57 53 5C 73 79 73 74 65 6D 33 32 5C 76 6D 78 33 32 74 6F 36 34 2E 65 78 65, Replace it with the characters C:\WINDOWS\system32\vmx32to64.exe, explain VideoDriver The self starting item points to system32 In the catalog vmx32to64.exe
②process explorer analysis
open explorer The lower window of the DLLs Dynamic link library

function Lab03-01.exe After the discovery 
stay Lab03-01.exe in ws2_32.dll and wshtcpip.dll Therefore, it indicates that there are network operations
③process monitor analysis
Get into Filter Add filter criteria to the window 

It was predicted that the program would be downloaded during the previous static analysis vmx32to64.exe file , Gu Zai run Lab03-01.exe Can after ctrl+F Search directly vmx32to64.exe after 
Found in windows\system32 Create a write under the path vmx32to64.exe File and in currentversion\run I created VideoDriver Key value of self starting item
Came to windows\system32 View under directory vmx32to64 file


View its MD5 Value found to be the same as Lab03-01.exe equally , So come to the conclusion Lab03-01.exe Copy yourself to windows\system32 Under the table of contents , In the above registry analysis VideoDriver The key value of the self starting item points to windows\system32 The next path vmx32to64.exe
④ApateDNS Network access analysis

Found that it visited www.practicalmalwareanalysis.com This web site
ApateDNS Refer to the article for virtual network configuration 《 Malicious code analysis practice —— Use Apatedns and Inetsim Simulate the network environment 》
4. The experimental conclusion
Lab03-01.exe To copy itself to system32 Under the table of contents , And start up automatically
And Lab03-01.exe Run to make access www.practicalmalwareanalysis.com website
边栏推荐
- ASP. Net core permission system practice (zero)
- How high can C language reach by self-study alone?
- PHP generate schedule
- Win10 professional edition user name modification
- Several methods of importing ThinkPHP
- [CEGUI] log system
- 高通平台如何修改特殊电压
- 2022 Taobao 618 Super Cat Games introduction 618 super cat games playing skills
- 容器江湖的爱恨情仇
- Implementation principle of redisson distributed lock
猜你喜欢

Win10 professional edition user name modification

Properties Chinese garbled code

容器江湖的爱恨情仇

How to play the 2022 Taobao 618 Super Cat Games? What are the strategies for the Super Cat Games
![[machine learning] practice of logistic regression classification based on Iris data set](/img/c6/0233545d917691b8336f30707e4636.png)
[machine learning] practice of logistic regression classification based on Iris data set

Is the acceptance standard a test case?

机器学习不是你想用,想用就能用

properties中文乱码

Pseudo static setting of access database in win2008 R2 iis7.5
![[Wayland] Weston multi screen display](/img/58/698e2cc790d3dbef9260cb2ad690d8.jpg)
[Wayland] Weston multi screen display
随机推荐
MQTT 协议中文版
Implementation principle of redisson distributed lock
Simple use of autojs
Solution to invalid small program scroll into view
pycharm 查看opencv当前的版本
On the improvement of 3dsc by harmonic shape context feature HSC
数组,整型,字符变量在全局和局部的存在形式
One test for twoorthree years, recording some thoughts on test exchange experience
Get array median
2. factory mode
The solution of Lenovo notebook ThinkPad t440 WiFi dropping all the time
Pseudo static setting of access database in win2008 R2 iis7.5
[Wayland] Wayland introduction and customized guidance
Introduction to IOT
一测两三年,记测试交流经验的一些感想
[machine learning] practice of logistic regression classification based on Iris data set
93. obtain all IP addresses of the Intranet
Chromebook system without anti-virus software
Propagation of transactions
Fiddler automatically saves the result of the specified request to a file