A forum for reverse engineering, OS internals and malware analysis 

Search found 56 matches: Cuckoo Sandbox

Searched query: cuckoo sandbox

ignored: sandbox

 Go to advanced search

Re: Virustotal scan

 by voroojax ¦  Mon Dec 29, 2014 5:04 am ¦  Forum: Newbie Questions ¦  Topic: Virustotal scan ¦  Replies: 2 ¦  Views: 4966

scan is defenitfly static(scantime as you referred) but some samples get into cuckoo sandbox, but you should notice that cuckoo is not an AV, it's sandbox and show the dynamic activity.

Re: Virustotal scan

 by sysopfb ¦  Sun Dec 28, 2014 12:47 am ¦  Forum: Newbie Questions ¦  Topic: Virustotal scan ¦  Replies: 2 ¦  Views: 4966

According to this
http://blog.virustotal.com/2012/07/viru ... ation.html

They use a cuckoo sandbox, I would imagine tweaked so they can generate their reports properly.

Re: WinNT/Phase - fileless trojan

 by Vult ¦  Thu Dec 25, 2014 4:37 pm ¦  Forum: Malware ¦  Topic: WinNT/Phase - fileless trojan ¦  Replies: 28 ¦  Views: 28706

Xylitol wrote:
Vult wrote:i tried hexing
if you come just for that then you're not welcome here.
Also a simple cuckoo should do the tricks to get gate urls, in attach, php page from the ram scrapper plugin.
not just for that buddy. but to learn real reversing.

Re: WinNT/Phase - fileless trojan

 by Xylitol ¦  Thu Dec 25, 2014 3:20 pm ¦  Forum: Malware ¦  Topic: WinNT/Phase - fileless trojan ¦  Replies: 28 ¦  Views: 28706

Vult wrote:i tried hexing
if you come just for that then you're not welcome here.
Also a simple cuckoo should do the tricks to get gate urls, in attach, php page from the ram scrapper plugin.

Needed Malware Analysis Features

 by evelyette ¦  Mon Dec 15, 2014 9:55 pm ¦  Forum: General Discussion ¦  Topic: Needed Malware Analysis Features ¦  Replies: 0 ¦  Views: 4639

... We already have automated malware analysis systems like Malwr (Cuckoo), Joe Sandbox, Anubis, etc. This topic is meant to shed some light on the features you would like ...

Re: Automated Malware Environments

 by frank_boldewin ¦  Sat Dec 13, 2014 4:42 pm ¦  Forum: Malware ¦  Topic: Automated Malware Environments ¦  Replies: 12 ¦  Views: 10678

Cuckoo supports VBOX, VMWARE and QEMU KVM. Further it has support for Volatility. The latet Version has a branch to a new API-Monitor, which will integrate in the master branch in the near future. Another plugin is zer0m0n ...

Re: Automated Malware Environments

 by evelyette ¦  Thu Dec 11, 2014 6:09 pm ¦  Forum: Malware ¦  Topic: Automated Malware Environments ¦  Replies: 12 ¦  Views: 10678

Hello, TK_: The malwr uses Cuckoo - I've updated the initial post to make this clear. EP_X0FF: Thank you for your comment, I'll take a closer look. rnd.usr: I'm aware of the Drakvuf. Thank you all for your provided answers, but if anybody ...

Re: Automated Malware Environments

 by TK_ ¦  Thu Dec 11, 2014 8:24 am ¦  Forum: Malware ¦  Topic: Automated Malware Environments ¦  Replies: 12 ¦  Views: 10678

your missing cuckoo.

Re: Malware analysis - Buster Sandbox Analyzer

 by rnd.usr ¦  Tue Jul 08, 2014 11:25 am ¦  Forum: Tools/Software ¦  Topic: Malware analysis - Buster Sandbox Analyzer ¦  Replies: 314 ¦  Views: 256425

Have you looked how for example camas or vt/malwr (vbox vm) do this monitoring? Well, yes. First of all is Cuckoo using Cuckoomon: https://github.com/cuckoobox/cuckoomon for it's hooking and monitoring. Then there's the Behavior-plugin: https://github.com/cuckoobox/cuckoo/blob/master/modules/processing/behavior.py ...

Re: Malware analysis - Buster Sandbox Analyzer

 by EP_X0FF ¦  Tue Jul 08, 2014 7:19 am ¦  Forum: Tools/Software ¦  Topic: Malware analysis - Buster Sandbox Analyzer ¦  Replies: 314 ¦  Views: 256425

... and dumpguestcore and 2 tools(API-sniffer and RWX-dumper). It's not the best tool but it's always fun to create your own thing. I've tried Cuckoo but the behavioral function never works for me. The problem is that my tools kinda sucks. I have no program to monitor the I/O(filemon sucks ...