Some questions to be answered during Malware Analysis
Do you like this story?
Bussiness questions may include the following key questions :-
- What is the purpose of malware?
- How to get rid of that malware?
- How did it get there?
- Who may be targetting us?
- What did they steal?
- How long it has been here and infecting us?
- Does it spread on its own?
- How to find it on other machines?
- How to prevent this to infect us any further?
- What network-based indicators can reveal the presence and activity of malware?
- What host-based indicators can reveal the presence and activity of malware?
- Is the malware persistent? What is the mechanism to keep it running after rebooting of machine?
- Is the program based on some other tool?
- Malware is written in which language?
- When the program was written, compiled and installed?
- Is the program packed? Which packer is used for this purpose?
- Does the program has any anti-debugging functionality?
- Doest the program include any rootkit?
These were some of the questions that may help you to reach some conclusion in ur "malware analysis" if answered.
Subscribe to:
Post Comments (Atom)
1 Responses to “Some questions to be answered during Malware Analysis”
June 22, 2011 at 1:00 AM
Wonderful collection of questions. These are very useful for me to learn more about this. Thanks for sharing.
Post a Comment