Malware memory analysis for non-specialists : investigating publicly available memory images for Prolaco and SpyEye / by R. Carbone.: D68-6/155-2013E-PDF

This technical memorandum examines how an investigator can analyse an infected Windows memory dump. The author investigates how to carry out such an analysis using Volatility and other investigative tools, including data carving utilities and anti-virus scanners. Volatility is a popular and evolving open source-based memory analysis framework upon which the author has proposed a memory-specific methodology for aiding fellow novice memory analysts. The author examines how Volatility can be used to find evidence and indicators of infection. This technical memorandum is the second in a series concerning Windows malware-based memory analysis. This current work examines two memory images infected with Prolaco and SpyEye, respectively.

Permanent link to this Catalogue record:
publications.gc.ca/pub?id=9.821332&sl=0

Publication information
Department/Agency Canada. Defence R&D Canada.
Title Malware memory analysis for non-specialists : investigating publicly available memory images for Prolaco and SpyEye / by R. Carbone.
Series title Technical Memorandum ; 2013-155
Publication type Series - View Master Record
Language [English]
Format Electronic
Electronic document
Note(s) "October 2013."
Includes bibliographical references.
Publishing information [Ottawa] : Defence Research and Development Canada, c2013.
Author / Contributor Carbone, Richard.
Description xiv, 102 p. : tables, graphs.
Catalogue number
  • D68-6/155-2013E-PDF
Subject terms Technical reports
Antivirus
Malware
Virus scanner
Request alternate formats
To request an alternate format of a publication, complete the Government of Canada Publications email form. Use the form’s “question or comment” field to specify the requested publication.
Date modified: