GREM試験無料問題集「GIAC Reverse Engineering Malware 認定」

When analyzing a ransomware sample you find code referencing CryptDeriveKey. What does this indicate?

A malware sample checks the registry key:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId
What is the MOST likely purpose?

What features should a malware analysis lab have to ensure effective analysis? (Choose Three)

正解:C,D,E 解答を投票する
What is the significance of finding extensive use of System.Reflection namespace in a .NET malware sample?

Which of the following are common flow control instructions used in malware? (Choose two)

Which of the following is the MOST reliable indicator that the payload is unpacked?

Which of the following are reasons malware might use the VirtualAllocEx function? (Choose Two)

In the context of RTF file analysis, what purpose does examining hexadecimal content serve?

What is a common sign that a PDF might be malicious?

Why would an analyst examine the timestamps within the metadata of a suspected malware file?

You are performing behavioral analysis on a malware sample that makes unusual DNS queries and writes data to a specific registry key.
Which actions should you take to further investigate this sample's behavior? (Choose three)

正解:A,B,D 解答を投票する
In the context of .NET reverse engineering, what is the primary purpose of examining the Intermediate Language (IL) code?

What is the primary objective of conducting a static analysis on a suspected malware file?