EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsHard

A security team is analyzing a suspicious executable found on a critical server. Initial static analysis reveals that the executable contains highly obfuscated code, making it difficult to understand its functionality. When executed in a sandbox environment, it attempts to modify system DLLs and inject code into legitimate processes. Which malware analysis technique would be most effective for understanding the full behavior of this executable, given its evasive characteristics?

  1. AHeuristic analysis
  2. BMemory forensics
  3. CDynamic analysis
  4. DSignature-based analysis
Show answer & explanation

Correct answer: C. Dynamic analysis

Given the obfuscated code and evasive behaviors like DLL modification and process injection, dynamic analysis in a controlled environment (like a sandbox) is crucial. It allows analysts to observe the malware's real-time actions, API calls, network communications, and file system changes as it executes, bypassing static obfuscation.

Why the other options are wrong

  • A. Heuristic analysis might flag suspicious behavior but won't provide the detailed, step-by-step understanding of the malware's full execution path and evasive techniques as dynamic analysis would.
  • B. Memory forensics is useful for analyzing artifacts left in memory after execution, but dynamic analysis focuses on observing the execution itself to understand the full behavior from start to finish.
  • D. Signature-based analysis relies on known patterns and would likely fail against highly obfuscated, potentially new malware.

Dynamic Malware Analysis

The process of executing malware in a controlled environment (e.g., sandbox, virtual machine) to observe and analyze its real-time behavior, including API calls, network activity, and file system changes.

  • Effective against obfuscated and polymorphic malware.
  • Requires a safe, isolated environment.
  • Provides insights into runtime functionality and evasive techniques.

Memory trick: To see the 'dynamic' dance, you must make it perform.

More Malware Threats questions