Friday, December 14, 2018

Basic Malware Checking - PART II - Using IDA Pro

IDA Pro's version: v 7.0

1) Go to "Options"->"General...", and check the options below:
Comments
Repeatable comments
Auto comments

2) Go to "View"->"Open subviews"->"Segments", and see if the application is packed.

3) Go to "View"->"Open subviews"->"Imports", and see if there is any risky API being used.

4) Go to "View"->"Open subviews"->"Strings", and see if there is any keyword suspicious.

No comments:

Post a Comment