A Quick Malware Teardown

Published: 06 August 2021    Last Updated: 05 July 2023

A follower sent me a suspicious looking file recently to get my opinion on its behaviour and to see if I could pull out a little detail on how it’s working. “Suspicious looking” because at the time, it was getting a zero score on VirusTotal but it appeared to be doing something just a little dodgy in the background. I wanted to post some notes around my quick tear down of the malware show that since so much malware is poorly written and obfuscated you can often do a large amount of analysis of a file’s behaviour in a short period of time.

