$20
Lab Description: Using dynamic analysis tool Process Monitor, apply the correct filters to identify relevant information from the sample.
Lab Environment: Use of variety of tools is needed for this lab. It is recommended to do this lab in a virtualized environment. The tools we will be using are:
· Process Monitor (ProcMon)
· Text editor
· Process Hacker 2
Lab Files that are Needed:
· CryptoLocker.pml
· CryptoLocker.txt
Lab Exercise 1 – Using Process monitor
Learning Outcomes 1, 2, & 3
Use CryptoLocker.txt & CryptoLocker.PML. The TXT file is a capture of process activity at the time of the infection, the .PML is a log from Process Monitor during the same attack.
Identify the malicious process, what is its process ID (PID)?
What process started this process?
Describe the process activity for the malware.
Did the malware modify any registry keys? If so, what is the significance of the keys it modified?