Initial static analysis
To help us out in terms of our static info gathering, here is a list of the information that we need to obtain:
- File properties (name, size, other info)
- Hash (MD5, SHA1)
- File type (including header information)
- Strings
- Deadlisting (highlight where we need information)
At the end of the initial analysis, we will have to summarize all the information we retrieved.
Initial file information
To get the filename, file size, hash calculations, file type, and other information regarding the file, we will be using CFF
Explorer. When opening the file, we might encounter an error message when using the latter, as can be seen in the following screenshot:
This error is caused by MS Windows' virus protection feature. Since we are in a sandboxed environment (under a virtualized guest environment), it should be okay to disable this. Disabling this feature in a production environment can expose risks for the computer getting compromised by malware.
To disable this feature in Windows, select...