A forum for reverse engineering, OS internals and malware analysis 

Search found 56 matches: Cuckoo Sandbox

Searched query: cuckoo sandbox

ignored: sandbox

 Go to advanced search

Re: ZeroAccess (alias MaxPlus, Sirefef)

 by unixfreaxjp ¦  Tue Jul 30, 2013 6:00 am ¦  Forum: Malware ¦  Topic: ZeroAccess (alias MaxPlus, Sirefef) ¦  Replies: 557 ¦  Views: 578597

... stuff and the autostart. Just a recent update: Tested in "ALL" online sandbox, you name it, are all crashed. Cuckoo also crashed, only one VM survived this (the MS one *smile*) Sysinternals stuff is causing ...

Re: ZeroAccess (alias MaxPlus, Sirefef)

 by unixfreaxjp ¦  Mon Jul 29, 2013 8:39 pm ¦  Forum: Malware ¦  Topic: ZeroAccess (alias MaxPlus, Sirefef) ¦  Replies: 557 ¦  Views: 578597

... Apphelp.dll VERSION.dll Forget it if you want to run sample in Cuckoo or sandbox: https://lh4.googleusercontent.com/-qiQsW6y88oE/UfamtV0ABCI/AAAAAAAANMk/BU3WmhfQL40/s422/012.jpg ...

Re: Win32/Kovter

 by Horgh ¦  Thu Jun 27, 2013 1:36 pm ¦  Forum: Malware ¦  Topic: Win32/Kovter ¦  Replies: 39 ¦  Views: 54768

And it's not even working, I successfully infected myself on my vmware machine without doing any modifications on the anti-* stuff. The malware performs successfully also on cuckoo sandbox ; so this is a big piece of crap.

Re: Win32/Zeus (alias Zbot)

 by unixfreaxjp ¦  Tue May 28, 2013 3:26 pm ¦  Forum: Malware ¦  Topic: Win32/Zeus (alias Zbot) ¦  Replies: 281 ¦  Views: 369366

... Jump to quick reversing on binary, finding the highlights as below which is not written in VT behavior analysis. For the rest of analysis pls see Cuckoo result on VT behavior analysis at the above URL, is accurate enough: Temporary file(bot logic) used: tmp (calling environment temp) %s%08x.%s ...

Re: Citadel (Zeus clone)

 by Cassiel ¦  Fri Jan 04, 2013 12:40 pm ¦  Forum: Malware ¦  Topic: Citadel (Zeus clone) ¦  Replies: 197 ¦  Views: 406978

@ EP_X0FF Well my idea was to use a VM with BSA in order to have a snapshot if things went wrong. I tried cuckoo also however I like the reporting from BSA a lot more then cuckoo. @ Buster_BSA You are most likely right, I am going to check this with procmon in order to see how ...

Re: Setting up personal malware analysis lab ?

 by Pernat1y ¦  Wed Dec 05, 2012 2:37 pm ¦  Forum: Newbie Questions ¦  Topic: Setting up personal malware analysis lab ? ¦  Replies: 8 ¦  Views: 10187

BTW, can anyone recommend software to run own sandbox (something like ZeroWine or Cuckoo sandbox)?

Re: Looking for a virus the uses anti sniffer tools for wind

 by Buster_BSA ¦  Sun Nov 04, 2012 3:35 pm ¦  Forum: Reverse Engineering and Debugging ¦  Topic: Looking for a virus the uses anti sniffer tools for windows ¦  Replies: 6 ¦  Views: 8446

Cuckoo Sandbox has an signature to detect anti sniffer and its like this: import re from lib.cuckoo.common.abstracts import ...

Malwasm - Offline debugger for malware's reverse engineering

 by N3mes1s ¦  Thu Oct 25, 2012 9:22 am ¦  Forum: Tools/Software ¦  Topic: Malwasm - Offline debugger for malware's reverse engineering ¦  Replies: 0 ¦  Views: 4719

... the guys behind malware.lu dbs. Presentation Malwasm is a tool based on Cuckoo Sandbox available here. Malwasm was designed to help people that do reverse engineering. Malwasm ...

Re: Malware analysis - Buster Sandbox Analyzer

 by Buster_BSA ¦  Mon Sep 24, 2012 8:51 pm ¦  Forum: Tools/Software ¦  Topic: Malware analysis - Buster Sandbox Analyzer ¦  Replies: 314 ¦  Views: 256425

Take a report generated by BSA and using it make other report in a more organized and categorized way. Then show me both so I can get an idea of what you would like to see.

Why use BSA and not Cuckoo? That´s something you must decide after trying both.

Re: Malware analysis - Buster Sandbox Analyzer

 by hanan ¦  Mon Sep 24, 2012 7:29 pm ¦  Forum: Tools/Software ¦  Topic: Malware analysis - Buster Sandbox Analyzer ¦  Replies: 314 ¦  Views: 256425

Could you please tell me why use BSA and not Cuckoo sandbox (under VirtualBox which doesn't have detection in malware yet AFAIK) ? I have actually tried ...