Malware Samples - PMA Chapter 1

11 Dec 2025

The first chapter in Practical Malware Analysis discusses the basics of static/dynamic analysis including the Portable Executable (PE) format, static/dynamic/runtime linking (DLLs), and packing/obfuscation. This chapter introduced some basic tools for static analysis of PE files such as PEView, Resource Hacker, and Dependency Walker. Four malware samples are included to reinforce what was taught in the chapter and gain some familiarity with the tools.

Samples:

  1. Malware Sample 1
  2. Malware Sample 2
  3. Malware Sample 3
  4. Malware Sample 4

Questions:

  1. Upload the sample to Virus Total.
  2. When were these files compiled?
  3. Are there any indications that either of these files are packed or obfuscated?
  4. Do any imports hint at what this malware does?
  5. Are there any other files or host-based indicators you could look for on infected systems?
  6. What network-based indicators could be used to find this malware on infected machines?
  7. What would you guess is the purpose of these files?

Feedback is welcome and encouraged! Please leave a comment below: