샘플
실행 전
실행 후
1차 확인
pestudio.exe
The file contains another file,signature: executable, location: .rsrc, offset: 0x00009240, size: 48640,1
The file contains another file,signature: executable, location: .rsrc, offset: 0x00015040, size: 5704,1
file,-,-,-,-,-,-,-,executable, offset: 0x00009240, size: 48640,- file,-,-,-,-,-,-,-,executable, offset: 0x00015040, size: 5704,-
DRIVER,102,0x00015040,executable (cpu: 32-bit),5704,5.41 %,4.015,Korean,4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 ,M Z .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. @ .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. BIN,101,0x00009240,executable (cpu: 64-bit),48640,46.12 %,4.279,Korean,4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 ,M Z .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. @ .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. .. ..
자신을 포함한 3개의 실행파일을 확인
ascii,40,0x0000004D,-,dos-message,-,!This program cannot be run in DOS mode. ascii,40,0x0000928D,-,dos-message,-,!This program cannot be run in DOS mode. ascii,40,0x0001508D,-,dos-message,-,!This program cannot be run in DOS mode.
2차 확인
CFF Explorer.exe
myExe.exe
MyDriver1.sys