Malware Analysis

Forensics CheatSheets

https://www.jaiminton.com/cheatsheet/DFIR/#arrow-up-right

Online Services

Offline antivirus

  • Windows Defender

  • Avast Antivirus (or any other antivirus)

Update the Antivirus, disconnect from internet the PC and scan the file.

PEpper

PEpper arrow-up-rightchecks some basic stuff inside the executable (binary data, entropy, URLs and IPs, some yara rules

Yara

Install

Prepare rules

Use this script to download and merge all the yara malware rules from github: https://gist.github.com/andreafortuna/29c6ea48adf3d45a979a78763cdc7ce9arrow-up-right Create the rules directory and execute it. This will create a file called malware_rules.yar which contains all the yara rules for malware.

Scan

ClamAV

Install

Scan

最后更新于