We have covered how a PE header could help you answer questions related to incident handling or a normal tactical report. Now, we will cover the following questions related to threat intelligence and how a PE header can help you answer them:
- When was this sample created?
Sometimes, it's a very important for threat researchers to know how old the sample is. Is it an old sample or a new variant, and when did the attackers actually start to plan their attacks in the first place.
PE header includes a value called TimeDateStamp in the file header. This value includes the exact date and time this sample was compiled, which can help answer this question and help threat researchers build their attack timeline. However, it's worth mentioning that it can also be forged.
- What's the country of origin of these attackers?
Was it from the US? From Russia? China? Or maybe from Iran? That can answer a lot about attacker's motivations...