TryHackMe | Introduction to Antivirus WriteUp

 

Understand how antivirus software works and what detection techniques are used to bypass malicious files checks.

Link- https://tryhackme.com/room/introtoav



What was the virus name that infected John McAfee’s PC?

brain

Which PC Antivirus vendor implemented the first AV software on the market?

mcafee

Antivirus software is a _____-based security solution.

host

Which AV feature analyzes malware in a safe and isolated environment?

emulator

An _______ feature is a process of restoring or decrypting the compressed executable files to the original.

unpacker

What is the sigtool tool output to generate an MD5 of the AV-Check.exe binary?

f4a974b0cf25dca7fbce8701b7ab3a88:6144:AV-Check.exe


Use the strings tool to list all human-readable strings of the AV-Check binary. What is the flag?

THM{Y0uC4nC-5tr16s}


Which detection method is used to analyze malicious software inside virtual environments?

dynamic detection


That’s it! See you in the next Room :)



Comments

Eonrec

Popular posts from this blog

TryHackMe | Introduction To Honeypots Walkthrough

TryHackMe | Redline Walkthrough

TryHackMe | Wireshark: The Basics Walkthrough