Challenge
Utilizing your newly minted Cuckoo VM and the Locky sample, attempt to answer the following questions:
- Are there any anti-analysis tricks that are being utilized by the sample? If so, which ones?
- Is the sample packed? If so, what is indicative of the use of a packer in the sample?
- If the sample is packed, what is the SHA256 of the unpacked sample?
- Are there any other suspicious indicators in the process or its memory? If so, what are they?