Using Reverse Engineering to Face Malware
Artículo académico
Visión General
Visión General
Abstracto
This paper is a product of the research Project "Cyber Security Architecture for Incident Management" developed in the Colombian School of Engineering Julio Garavito in the year 2018. Introduction: Reverse engineering involves deconstructing and extracting knowledge about objects. The use of reverse engineering in malware analysis is extremely useful in understanding the functionalities and purposes of a suspicious sample. Methods: This paper makes use of Radare which is one of the most popular open source tools for reverse engineering, with the aim of dealing with malware. Results: A use case related to hacking of anti-sandbox malware is presented, in such a way that it is possible to analyze the behavior of the sample using a sandbox.