VirusTotal Multisandbox += Sangfor ZSand

VirusTotal multisandbox project welcomes Sangfor ZSand.  The ZSand currently focuses on PE files,with extensions to other popular file types like javascript and Microsoft office to be released soon.In their own words:ZSand, developed by Sangfor Te… Continue reading VirusTotal Multisandbox += Sangfor ZSand

Seeking recommendations/warnings for creating a server for malware sample upload and analysis

I am trying to conceptualize a server where users can upload potentially dangerous malware samples to a server. They would not need to be stored in the file system per se but kept in memory long enough to be analyzed by other programs/libr… Continue reading Seeking recommendations/warnings for creating a server for malware sample upload and analysis

[SANS ISC] Sandbox Evasion Using NTP

I published the following diary on isc.sans.edu: “Sandbox Evasion Using NTP“: I’m still hunting for interesting (read: “malicious”) Python samples. By reading my previous diaries, you know that I like to find how attackers implement obfuscation and evasion techniques. Like yesterday, I found a Python sample that creates a thread

The post [SANS ISC] Sandbox Evasion Using NTP appeared first on /dev/random.

Continue reading [SANS ISC] Sandbox Evasion Using NTP