A forum for reverse engineering, OS internals and malware analysis 

Search found 56 matches: Cuckoo Sandbox

Searched query: cuckoo sandbox

ignored: sandbox

 Go to advanced search

Re: VBoxAntiVMDetectHardened mitigation X64 only (07/01/16)

 by EP_X0FF ¦  Wed Jan 20, 2016 6:45 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757806

... including bullshit. * Pafish (Paranoid fish) * Some anti(debugger/VM/sandbox) tricks used by malware for the general public. [*] Windows version: ... name ... OK [*] cpuid Intel wrong value for processor name ... OK [-] Cuckoo detection [*] Looking in the TLS for the hooks information structure ...

Re: VBoxAntiVMDetectHardened mitigation X64 only (08/11/15)

 by enkidu ¦  Thu Nov 26, 2015 5:13 am ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757806

have you seen modified cuckoo (by brat) which have anti vm detection technique? does your suggested method work better? am jut trying to make my cuckoo function well, so i need to find best technique possible to hide vm from malware

Re: VBoxAntiVMDetectHardened mitigation X64 only (08/11/15)

 by EP_X0FF ¦  Mon Nov 16, 2015 7:26 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757806

thank you for this useful post. i use virtual machine for malware analysis with cuckoo. my questions are: 1. when i install virtual box (after disable networking, i get a msg: would you like to install this device software? Oracle corporation universal serial bus ...

Re: VBoxAntiVMDetectHardened mitigation X64 only (08/11/15)

 by nov5th ¦  Mon Nov 16, 2015 4:46 am ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757806

thank you for this useful post. i use virtual machine for malware analysis with cuckoo. my questions are: 1. when i install virtual box (after disable networking, i get a msg: would you like to install this device software? Oracle corporation universal serial bus ...

Re: Backdoor:Win32/Kawpfuni.A

 by Xylitol ¦  Thu Sep 03, 2015 6:52 pm ¦  Forum: Malware ¦  Topic: Backdoor:Win32/Kawpfuni.A ¦  Replies: 3 ¦  Views: 5211

... irc protocol and also interested by AhnLab, ViRobot, ESTsoft and PhysicalDrive0 Haven't looked further. http://i.imgur.com/BygtEx9.png From a cuckoo run: GET /bbs/install1_ok.php?no=0&id=v^086C1F25&sn=1406747&sc=5fb84e8bec4d5565b4be6dd0b73c1f0a HTTP/1.1 Accept: */* Accept-Encoding: gzip, deflate ...

Re: Win32 Rombertik

 by r32 ¦  Fri May 08, 2015 2:08 am ¦  Forum: Malware ¦  Topic: Win32/Rombertik ¦  Replies: 27 ¦  Views: 55055

Hi all, this sample was extracted Cuckoo Sandbox, but not because they have been deleted. In this url i found. http://t.co/yjP9oqxsQv http://cuckoo.killerinstinct.me/analysis/1587/ ...

Re: Cuckoo Sandbox

 by EP_X0FF ¦  Thu Feb 12, 2015 9:45 am ¦  Forum: Tools/Software ¦  Topic: Cuckoo Sandbox ¦  Replies: 1 ¦  Views: 6097

What the point of this spam?

Banned in Search?

http://www.kernelmode.info/forum/search ... oo+Sandbox

Cuckoo Sandbox

 by ilaloyka ¦  Thu Feb 12, 2015 6:52 am ¦  Forum: Tools/Software ¦  Topic: Cuckoo Sandbox ¦  Replies: 1 ¦  Views: 6097

This sandbox is very useful and changable. Everyone can develop it. http://www.cuckoosandbox.org/
malwr (https://malwr.com/) uses the sandbox but I think it can be more beaitful.

Re: Malware Families Using Raw Syscalls

 by EP_X0FF ¦  Mon Feb 09, 2015 10:28 am ¦  Forum: Newbie Questions ¦  Topic: Malware Families Using Raw Syscalls ¦  Replies: 21 ¦  Views: 28301

... (in case of UM hooks it wont get me proper syscall no) Thus defeating the purpose of finding syscalls no and writing code to outrun sandboxes like cuckoo. in case of hook @32bit/WOW64 { 0xB8 [service ordinal] XX XX XX } will get tampered and on runtime will give you different values. Perhaps a ...

Re: Malware Families Using Raw Syscalls

 by TheExecuter ¦  Mon Feb 09, 2015 9:36 am ¦  Forum: Newbie Questions ¦  Topic: Malware Families Using Raw Syscalls ¦  Replies: 21 ¦  Views: 28301

... (in case of UM hooks it wont get me proper syscall no) Thus defeating the purpose of finding syscalls no and writing code to outrun sandboxes like cuckoo. in case of hook @32bit/WOW64 { 0xB8 [service ordinal] XX XX XX } will get tampered and on runtime will give you different values. Perhaps a ...