Dynamiic Viet
Dynamiic Viet
Dynamiic Viet
Analyze Analyze
Debug
environment behavior
Harder
IOCs
network
registry files
activities
autorun processes
Process monitor
• Run procmon
• Set up filter
• Rename 9e7cf8e27c3c7989b28fcfb1ed7cf28326cac767453dcc329eee3f21b2d9f51a to malware.exe
• Run it
• Find following
• Created processes and their command lines
• Dropped files
• Malicious process
Practice time
Process hacker
Registry compare utility that allows you to quickly take a snapshot of your
registry and then compare it with a second one - done after doing system
changes or installing a new software product.
Here you can see all the registers of you CPU and
their values. Top selection makes general purpose
registers, which contain temporarily values, and
registers which are used for controlling program
flow.
41
Lazarus Recon Backdoor
42
Lazarus Recon Backdoor
43
Lazarus Recon Backdoor
44
Lazarus Recon Backdoor
45
Trifonov Vitalii
[email protected]