Dynamic Analysis of Window’s Based Malware Using Reverse Engineering: A Case Study of Exmatter
摘要
Malware analysis, is a crucial and cumbersome task, because of the continuously evolving characteristics of malware. Most of the malware damages the system resources or held them hostages for some unreasonable demands. Trojan is one of the most sought out malware by the attackers as it does destruction itself as well as it carries other types of malwares to the targets. This paper, proposes a framework for carrying out dynamic analysis of Trojan type malware, along with the mitigation methods and ways, by acquiring and executing the code at various stages of the malware in a controlled virtual environment. The experiment was carried out on, a virtual Window’s 11 machine, by following each step of the proposed framework. The analysis of the code is done using open source tools at various stages of the framework. The analysis carried out in the study results in identification of Indicators of Compromise (IOC) and strings that represent suspicious behavior and Tricks, Tactics and Procedures (TTP) of Exmatter malware, which further help to mitigate the effects of the attack.