Browse Definitions :
Definition

Malware Analysis Report (MAR)

A Malware Analysis Report (MAR) is a document that provides an in-depth breakdown about the functionality and risk of a new or evolving cyber threat. Typically, a MAR categorizes the malicious intent of a given piece of malware by how the code executes and what it was designed to steal. The documentation also lets readers know how to recognize signs of infection and how to mitigate risk. 

The National Cyber Awareness System, which is run by the U.S. Department of Homeland Security, disseminates Malware Analysis Reports in alerts, RSS feeds and opt-in newsletters. A typical MAR includes the following information: 

  • Summary -- explains who did the research.
  • Findings -- describes what the malware is designed to do.
  • Recommendations -- provides best practices for preventing infections and recovering from them.

A Malware Analysis Report (MAR) provides organizations with detailed analysis of a specific threat by manually reverse engineering the malicious code. First, the static properties of malware -- including header information, hashes, embedded strings and resources are often collected to provide researchers with compromise indicators. Next, the behavior of the malware will be observed and finally, engineers will manually try to reverse the code to understand how it works.

Generally, MARs are created by dedicated research teams, either in law enforcement, academia or security enterprises. For example, the United States Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) recently issued a joint malware analysis report on a new Trojan horse called HOPLIGHT. HOPLIGHT is a backdoor Trojan that has reportedly been used by an advanced persistent threat (APT) group in North Korea called Lazarus. The malware can read, write and move files. It can also create and kill processes and services, edit registry settings and upload or download files to (and from) a remote server. 

This was last updated in December 2019

Continue Reading About Malware Analysis Report (MAR)

SearchNetworking
  • network packet

    A network packet is a basic unit of data that's grouped together and transferred over a computer network, typically a ...

  • virtual network functions (VNFs)

    Virtual network functions (VNFs) are virtualized tasks formerly carried out by proprietary, dedicated hardware.

  • network functions virtualization (NFV)

    Network functions virtualization (NFV) is a network architecture model designed to virtualize network services that have ...

SearchSecurity
  • Android System WebView

    Android System WebView is a system component for the Android operating system (OS) that allows Android apps to display web ...

  • data masking

    Data masking is a method of creating a structurally similar but inauthentic version of an organization's data that can be used ...

  • computer worm

    A computer worm is a type of malware whose primary function is to self-replicate and infect other computers while remaining ...

SearchCIO
  • privacy compliance

    Privacy compliance is a company's accordance with established personal information protection guidelines, specifications or ...

  • contingent workforce

    A contingent workforce is a labor pool whose members are hired by an organization on an on-demand basis.

  • product development (new product development -- NPD)

    Product development, also called new product management, is a series of steps that includes the conceptualization, design, ...

SearchHRSoftware
  • talent acquisition

    Talent acquisition is the strategic process employers use to analyze their long-term talent needs in the context of business ...

  • employee retention

    Employee retention is the organizational goal of keeping productive and talented workers and reducing turnover by fostering a ...

  • hybrid work model

    A hybrid work model is a workforce structure that includes employees who work remotely and those who work on site, in a company's...

SearchCustomerExperience
  • Salesforce Trailhead

    Salesforce Trailhead is a series of online tutorials that coach beginner and intermediate developers who need to learn how to ...

  • Salesforce

    Salesforce, Inc. is a cloud computing and social enterprise software-as-a-service (SaaS) provider based in San Francisco.

  • data clean room

    A data clean room is a technology service that helps content platforms keep first person user data private when interacting with ...

Close