Deutsch

Digital Forensics

Malware Analysis

A suspicious file on its own says very little. It becomes interesting through three questions: what does it do? Where did it come from? And what would have let us catch it earlier?

A sealed glass chamber in a dark laboratory. Inside, a single object rests on a pedestal, lit from below; the room around it stays dark.

The method

Three levels of analysis

Effort rises sharply across the levels. So after the first pass we decide together with you how deep to go — for widespread commodity malware the analysis often ends at level one.

01

Static

file structure, strings, embedded resources and signatures — without execution

02

Dynamic

controlled execution in an isolated environment, observing file system, registry, processes and network

03

Reverse engineering

taking the code apart where obfuscation or packers block the first two levels

The result

What you get at the end

  1. 01

    Behavioural description

    what the sample actually does on an infected system

  2. 02

    Indicators of compromise

    file names, hashes, registry keys, network destinations

  3. 03

    Detection rules in a format your systems can take over directly

  4. 04

    Classification

    known family, similarities to earlier incidents, probable objective

  5. 05

    Recommendations for clean-up and for checking whether other systems are affected

01

The follow-through

Connecting to day-to-day operations

Indicators are only useful once they take effect somewhere. In environments running Strider we place them directly into the correlation, so that a second infection in the same network does not go unnoticed. Talion uses the same patterns for automatic isolation before an analyst even sees the alert.

02

The urgency

While the attack is still running

If the attack is still under way, analysis is not the first step. What counts then is containment — get in touch through Instant Response, and the analysis runs alongside. For a dependable reconstruction of the whole incident we fall back on Digital Forensics.

FAQ

Frequently asked questions

How long does a malware analysis take?

The first level produces a result within hours, often the same day. A dynamic analysis usually takes one to two days. Reverse engineering cannot honestly be predicted — with heavily obfuscated code it can turn into weeks. After the first pass we tell you what the next step would cost, before you commission it.

Do we have to send you the suspicious file ourselves?

You hand the sample over through a secured route we agree in advance — not as an email attachment. If you are unsure whether a file is executable at all, do not touch it and call us first. Mishandling regularly destroys exactly the traces we need.

What if the antivirus already deleted the sample?

There is usually still something left: the scanner quarantine, copies in temporary directories, traces in memory if the system is still running. Do not shut the machine down before we have spoken — memory is the most volatile source and the first one lost.

Do we get detection rules we can use ourselves?

Yes, and that is the actual purpose. You receive the indicators and rules in a format your existing systems can adopt — regardless of whether you use our products. A report you can only read changes nothing about your detection.

Can you tell us who is behind it?

We can tell you whether a sample belongs to a known family and what similarities exist to earlier incidents. That does not establish attribution to a particular group — one file is not enough for that. Anyone deriving a culprit from a malware sample is overstretching the finding.

Digital Forensics

More in this area

Network Forensics

Network traffic reveals what has long been deleted on endpoints. We reconstruct entry, lateral movement and exfiltratio…

View

Cloud Forensics

There is no disk to image in the cloud. We secure logs, configuration states and identity data before the provider rete…

View

Mobile Forensics

Company phones often hold more business secrets than any computer. We secure and examine them to an evidentiary standar…

View

Behavioural Forensics

Tools change, habits persist. We analyse how an attacker operates and derive where they will start next time.

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.