A walkthrough of static malware analysis on suspicious Windows PE samples using a REMnux and FLARE-VM lab environment. The investigation covers a layered methodology: hash identification, VirusTotal correlation, metadata inspection with ExifTool, string extraction with FLOSS, PE structure analysis with PEview and Detect It Easy, and capability mapping with CAPA. Key findings include registry persistence via autorun keys, process injection APIs (VirtualAlloc, WriteProcessMemory, CreateRemoteThread), embedded C2 domains, and obfuscated strings — all consistent with AsyncRAT-like RAT behavior. Results are mapped to MITRE ATT&CK for actionable SOC detection engineering.
Table of contents
Investigation WorkflowGet Allen Ace’s stories in your inboxIndicators of Malicious Behavior30 Impressions