Geoff Chappell - Software Analyst
List files created in \AppData\ , \Temp\ , or modifications to the Windows Registry. Conclusion & Remediation
[e.g., This archive contains a known Trojan variant.] xsxsxax.rar
[What does the file do when extracted or executed?] Static Analysis Hashes: MD5: [Insert MD5] SHA-256: [Insert SHA-256] List files created in \AppData\ , \Temp\ ,
To generate a helpful write-up, I wouldHowever, if this is a file you are investigating, File Name: xsxsxax.rar File Type: RAR Archive Initial Assessment: [e.g., Suspicious, Malicious, Benign] List files created in \AppData\