<aside> 🎯

Initial Triage [Definition] β†’ The first steps taken when receiving a suspicious file, assessing what it is and how dangerous it may be

</aside>

<aside>

High-Level Summary

</aside>

In the initial triage, various tools, both offline and online, are used to identify signs that the malware is packed. Indicators include high entropy levels, minimal imports, suspicious or obfuscated strings, and known packers like UPX. As the analysis progresses, it becomes clear that the packed file is compressed and possibly encrypted to conceal its true behavior. This includes hiding its code logic, Command and Control (C2) server addresses, and potential payloads such as ransomware.

<aside> ✏️

Definitions

</aside>


<aside>

Analysis Reviewed

</aside>

<aside>

Tools Used in Analysis

</aside>

Tool: Description:
PEStudio Tool for analyzing PE (Portable Executable Files) can examine suspicious artifacts
Detect it Easy (DIE) Tool for file type identification, enabling file inspection
Cyberchef Web source tool that allows encoding, encryption and creating binaries and hexdumps
PE-Sieve Used for malware unpacking
System Informer Tool used to monitor system resources and detect malware

image.png

<aside> πŸ“‚

File Properties

</aside>

Suspicious Signs Include:

<aside> βš™

Limited Imports Examples

</aside>

<aside> βš’οΈ

Tools in Usage & Analysis

</aside>

  1. Using PE-Studio to Find Suspicious Information from Malware

    By importing the malware file into PE-Studio, you are able to view imports, strings, and other various libraries of indicators that may lead to understanding of suspicious signs.

    Figure 1: Indication of Low Amount of Imports β€” Signifying Packed File due to compression or encryption

    Screenshot 2025-04-25 at 7.38.20 PM.png

    Figure 2: Reviewing the Entropy Levels β€” Normal Amount for Executable File

Screenshot 2025-04-25 at 7.39.39 PM.png

Figure 3: Observing Random Strings and Potential Obfuscation β€” String names like UPX (compressed file name), several random string names β€” which could indicate obfuscation or compression β€” because the real strings are hidden until runtime.

Screenshot 2025-04-25 at 7.42.53 PM.png

  1. Packer Identification using Detect It Easy (DIE)

Using DIE, the file was scanned to then detect the sample as β€œpacked” with UPX (Ultimate Packer for Executables) which is a common packer that compresses executables. This method can be used to maliciously hide malware payloads.

Screenshot 2025-04-25 at 10.33.51 PM.png

Figure 4: DIE showing the packer as UPX, and other information related to the OS, compiler, language written

  1. Entropy Analysis with CyberChef β€” Shannon Entropy Recipe