A forum for reverse engineering, OS internals and malware analysis 

Search found 56 matches: Cuckoo Sandbox

Searched query: cuckoo sandbox

ignored: sandbox

 Go to advanced search

Re: Malware analysis - Buster Sandbox Analyzer

 by Buster_BSA ¦  Fri Aug 03, 2012 7:31 pm ¦  Forum: Tools/Software ¦  Topic: Malware analysis - Buster Sandbox Analyzer ¦  Replies: 314 ¦  Views: 256425

... at the list of exported functions and then run something like: rundll32.exe file.dll,installA One example: Flame. Take a look here: http://blog.cuckoosandbox.org/2012/05/29/cuckoo-in-flame/

Re: Malware Analyzer

 by nex ¦  Sun Feb 06, 2011 10:14 am ¦  Forum: Tools/Software ¦  Topic: Malware Analyzer ¦  Replies: 16 ¦  Views: 21957

Yes, virtualization detection is one of my main concerns. That's the main reason why I didn't want Cuckoo to be VirtualBox-dependent, nor dependent to any other product. I'm still wondering if it is better to work on finding a proper solution to safely virtualize analysis ...

Re: Malware Analyzer

 by nex ¦  Sun Feb 06, 2011 9:52 am ¦  Forum: Tools/Software ¦  Topic: Malware Analyzer ¦  Replies: 16 ¦  Views: 21957

... there are conditions in which the capability to process high volumes of malwares is more important than failing on few of them. And still since Cuckoo makes you able to post process analysis results, you can set triggers to identify malwares that successfully detects your virtualization environment. ...

Re: Malware Analyzer

 by Buster_BSA ¦  Sun Feb 06, 2011 9:46 am ¦  Forum: Tools/Software ¦  Topic: Malware Analyzer ¦  Replies: 16 ¦  Views: 21957

1. Well, you have to consider that Cuckoo is not meant to be used as a mainstream desktop product. It is meant for analysts, better if it is deployed in a production environment (as it was designed to be automated, concurrent and eventually ...

Re: Malware Analyzer

 by nex ¦  Sun Feb 06, 2011 9:23 am ¦  Forum: Tools/Software ¦  Topic: Malware Analyzer ¦  Replies: 16 ¦  Views: 21957

I reply to you, point by point. 1. Well, you have to consider that Cuckoo is not meant to be used as a mainstream desktop product. It is meant for analysts, better if it is deployed in a production environment (as it was designed to be automated, concurrent ...

Re: Malware Analyzer

 by Buster_BSA ¦  Sun Feb 06, 2011 8:14 am ¦  Forum: Tools/Software ¦  Topic: Malware Analyzer ¦  Replies: 16 ¦  Views: 21957

Cuckoo is another Windows malware analyzer running under Linux.

Image

That´s the main reason why I coded Buster Sandbox Analyzer.