What strings do you see statically in the binary

Assignment Help Other Subject
Reference no: EM132266934

Question 1. Analyze the malware found in the file Lab09-01.exe using OllyDbg and IDA-Pro to answer the following questions.
a. How can you get this malware to install itself?
b. What are the command-line options for this program? What is the password requirement?
c. How can you use OllyDbg to permanently patch this malware, so that it doesn't require the special command-line password?
d. What are the host-based indicators of this malware?
e. What are the different actions this malware can be instructed to take via the network?
f. 6. Are there any useful network-based signatures for this malware?

Question 2. Analyze the malware found in the file Lab09-02.exe using OllyDbg to answer the following questions.
a. What strings do you see statically in the binary?
b. What happens when you run this binary?
c. How can you get this sample to run its malicious payload?
d. What is happening at 0x00401133?
e. What arguments are being passed to subroutine 0x00401089?
f. What domain name does this malware use?
g. What encoding routine is being used to obfuscate the domain name?
h. What is the significance of the CreateProcessAcall at 0x0040106E?

Question 3. Given vulnerableserver.exe, use Windows 10, Windbg, and Kali Linux to write an exploit string. Your final deliverable should be:
a. A screen shot of the corrupted stack

2223_Screen shot.jpg

b. A screenshot of your exploit (from Kali Linux)

Specifics:
1) Please leave your EIP as a "dummy placeholder" (0x42424242 in my screenshot above) (no need to find the address of JMP ESP (or equivalent))
2) Please set a 0xCC as the first character of your payload
3) You must store your student number as the following digits of the payload. Make sure to mask off any illegal characters.

Attachment:- PROG8300 - Assignment.rar

Reference no: EM132266934

Questions Cloud

Do you believe that the structure will change : If your preferences do not fit the current structure of your organization, do you believe that the structure will change? Will you consider leaving.
Build Renovatech Inc pro forma financial statements : Financial statements Analysis Assignment - Build Renovatech Inc.'s pro forma financial statements based on the assumptions
Examine the various applications of the law : Examine the various applications of the law within the health care system. Analyze how such various applications of the law affect decisions in the development.
Analyze cultural and legal challenges the company : Analyze your selected company with micro and macro environmental forces by using SWOT analysis.
What strings do you see statically in the binary : PROG8300 - What strings do you see statically in the binary and What encoding routine is being used to obfuscate the domain name
Intentional discrimination by employer against an employee : Intentional discrimination by an employer against an employee is. Which of the following is true about Kiva.og per the Harvard Case Study?
Discuss overarching duties of health care governing board : Prevailing wisdom reinforces the fact that working in U.S. health care administration in the 21st Century requires knowledge of the various aspects of health.
Research supplier evaluation : Research supplier evaluation. When evaluating supplier's financial stability, what are some key indicators to consider? What are some other characteristics.
Assuming deterministic demand and no shortages : Assuming deterministic demand and no shortages, develop an ordering plan for this company using the Wagner-Whitin algorithm.

Reviews

inf2266934

9/1/2019 2:24:31 AM

Perfectly done work I am surprised to see that how your weritre has managed to write a quality work in such a limited time.

len2266934

3/26/2019 10:21:29 PM

Marking Rubric: Q1: 30% Q2: 30% Q3: 40% Partial marks awarded for partial answers, but all answers must support your observations/conclusions. Standard deductions: 5% for not having name and assignment # in your Word document 10% for zipping submission 25% for submitting screenshots not inserted/formatted into Word document 100% for any question that does not include supporting screenshots 100% for any question whose screenshots do not have date/time stamp or date/time

len2266934

3/26/2019 10:21:08 PM

Please include screen shots(full screen only) of all tool output that supports your answers to the questions. Paste these screenshots into a MS Word document, add required text/explanation/annotations and submit before due date. The required executable files for 1 and 2 are found in the practical malware zipfile and vulnerableServer.exe can be found on eConestoga in a file named PROG8300_W19_Assignment3_files.zip ( have extracted and sent it along with this document)

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd