Malware Behavior: Malware Analysis CSCI 4976 - Fall 2015 Branden Clark
Malware Behavior: Malware Analysis CSCI 4976 - Fall 2015 Branden Clark
Malware Analysis
CSCI 4976 - Fall 2015
Branden Clark
• PMA Lab11-01.exe
Ciphertext is in memory
Encryption keys are in memory
• right away…
– AdjustTokenPrivileges(...)