Windows Virus Sample Analysis

Job ID: 39993940

Budget: $15 – $25 USD

I have a Windows-based executable that is behaving like a virus and I need a thorough technical analysis of it. I will supply the sample in its original form; from there, I’m looking for a complete breakdown of how it operates, what it modifies, and any indicators of compromise it leaves behind.

Static and dynamic techniques are both welcome—feel free to use IDA, Ghidra, x64dbg, Wireshark, Procmon, or any other tools you usually rely on. A controlled sandbox or VM is expected so my own environment stays untouched.

Deliverables I need from you:
• A written report that explains the infection vector, persistence or spreading mechanism, payload behaviour, and any obfuscation or packing observed.
• A list of clear IOCs: file hashes, registry keys, domains, IPs, mutexes, strings, etc.
• Practical removal and mitigation steps that a Windows administrator can follow.
• (Optional but appreciated) YARA or Sigma rules that reliably detect this sample and its close variants.

Please document each stage of your approach so I can follow the reasoning behind your findings. Let me know the estimated turnaround and any constraints before we begin, and I’ll provide the sample right away.
Related categories: Reverse Engineering