Analyzing Malicious Files For Writing Network Signatures
ID: c4c69395-5616-5c1d-93d5-5b84d307230e
STIX ID: report--c4c69395-5616-5c1d-93d5-5b84d307230e
Feed Name: Zscaler Security Research Blog
Threat Score
This blog-style analysis demonstrates how to statically analyze a UPX-packed Trojan (associated with the Koobface worm) delivered from a fake antivirus site, showing steps to unpack the binary, use IDA Pro to extract strings, identify persistence via Run registry entries, and derive HTTP URL patterns and domains that can be used as network-based IOCs and signatures to detect and block the malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
