<aside>
π―
Initial Triage [Definition] β The first steps taken when receiving a suspicious file, assessing what it is and how dangerous it may be
</aside>
<aside>
High-Level Summary
</aside>
In the initial triage, various tools, both offline and online, are used to identify signs that the malware is packed. Indicators include high entropy levels, minimal imports, suspicious or obfuscated strings, and known packers like UPX. As the analysis progresses, it becomes clear that the packed file is compressed and possibly encrypted to conceal its true behavior. This includes hiding its code logic, Command and Control (C2) server addresses, and potential payloads such as ransomware.
<aside>
βοΈ
Definitions
</aside>
- Payload β Part of malware that carries out malicious action
- Command and Control β Remote servers that malware communications with to receive instructions, take data and download more payloads
- Imports β Functions that a program calls from external libraries (IE: Windows API)
- Entropy β The measurement of randomness of a system
- Packed Malware β Malicious code that uses compression or encryption to hide its malicious features
- PID β Process Identification Number, unique numerical identifier assigned to each running process in an operating system
- DLL β Dynamic Linked Lists, a file containing reusable code and data that can be used by multiple programs at the same time
<aside>
Analysis Reviewed
</aside>
- File Properties π It is important to understand the file itself and what may suspicious. Since the file contains the information related to malware, understanding its properties can provide more insight into what the file contains and its behaviors. Here are some basic file properties to review:
- Entropy Levels π**:** Entropy Levels showcase how random or uncertainty there is in a variables possible outcomes. Higher entropy levels may signify packed file, compressed or encrypted due to the increase amount of randomness.
- Limited Imports βοΈ: Signify packed binary, as the program plans to load additional functionality after unpacking itself.
- String Analysis π§΅: Large amounts of irrelevant/random strings, or encrypted strings that are hiding actual malware amongst the noise. Lack of meaningful strings could indicate suspiciscion of obfuscation.
<aside>
Tools Used in Analysis
</aside>
| Tool: |
Description: |
| PEStudio |
Tool for analyzing PE (Portable Executable Files) can examine suspicious artifacts |
| Detect it Easy (DIE) |
Tool for file type identification, enabling file inspection |
| Cyberchef |
Web source tool that allows encoding, encryption and creating binaries and hexdumps |
| PE-Sieve |
Used for malware unpacking |
| System Informer |
Tool used to monitor system resources and detect malware |
-
PEStudio

-
Detect it Easy

-
CyberChef

-
Pe-Sieve

-
System Informer

<aside>
π
File Properties
</aside>
Suspicious Signs Include:
- File Name
- Are there any random letters/numbers (ie: igf395043.exe)?
- Double extensions (ie: receipt.pdf.exe)
- This may imply someone disguising the file for something different than intended.
- File Size
- Small files
- Typically, full malware programs are larger as they have to handle networking, encrypt data, and set persistence using registry ΒΉ. If an executable is tiny, it may be a loader as it functions for specific part of the loader such as downloading or decrypting.
- Large files
- Larger files may be packed with junk or obfuscation, especially if larger than expected for a basic malware executable.
<aside>
β
Limited Imports Examples
</aside>
- Few Import Functions
- Showcase a sign of suspicion, which is an indication of packing.
- Imports and Related Activities
- Network Activity
- InternetOpen
- connect
- HttpOpen
- File Operations
- CreateFile
- WriteFile
- DeleteFile
- Process Control
- CreateProcess
- VirtualAlloc
- WriteProcessMemory
<aside>
βοΈ
Tools in Usage & Analysis
</aside>
-
Using PE-Studio to Find Suspicious Information from Malware
By importing the malware file into PE-Studio, you are able to view imports, strings, and other various libraries of indicators that may lead to understanding of suspicious signs.
Figure 1: Indication of Low Amount of Imports β Signifying Packed File due to compression or encryption

Figure 2: Reviewing the Entropy Levels β Normal Amount for Executable File

Figure 3: Observing Random Strings and Potential Obfuscation β String names like UPX (compressed file name), several random string names β which could indicate obfuscation or compression β because the real strings are hidden until runtime.

- Packer Identification using Detect It Easy (DIE)
Using DIE, the file was scanned to then detect the sample as βpackedβ with UPX (Ultimate Packer for Executables) which is a common packer that compresses executables. This method can be used to maliciously hide malware payloads.

Figure 4: DIE showing the packer as UPX, and other information related to the OS, compiler, language written
- Entropy Analysis with CyberChef β Shannon Entropy Recipe