reg practical PE header analysis

"Mayank.2.Bhatnagar" <[email protected]> Wed, 29 Sep 2010 17:08:41 +0530
Newsgroups gmane.comp.security.honeypots
Message-ID <51B335651C9A0C4EA520D47F23A580B414E2F160CF@SINNODMBX001.TechMahindra.com>
Hi all,

This is in reference to some experiments and on going work on PE header ana=
lysis of binaries to identify whether a binary is malicious or non-maliciou=
s.

It is made out that looking at PE header itself, one can make out that the =
captured binaries are suspicious, malicious or not.

What do you feel is the practicality of results achieved? Did anyone reach =
any prominent practical result, which could be achievable in real time?

Looking forward for some views..... :-)


Regards,
Mayank=20