Introducing UltraFast SNDBOX! the fastest most scalable solution in the industry, providing accurate verdicts powered by deep learning in under 60 seconds of dynamic analysis - for millions of files.
Detect 0-day and evasive malware attacks fast and accurately.
SNDBOX += VirusTotal;
We are excited to join VirusTotal's MultiSandbox.
All @virustotal files analyses are available for all of our registered users at https://t.co/jHfNEbN9s9
New type of attack on #OLE (Office) files to avoid AV detection.
Malware Doesn't execute anything, leaves a #GenericPersistence mechanism to execute after machine restart.
21 \ 61 on VirusTotal
IOCS:
solsin[.]top/w1
eb49ee744d8a05c877681c68da251720
https://t.co/7KeQx4dV3e
@Ledtech3 It doesnt detect the sandbox, it tries to avoid being detected by only dropping a file that will execute after machine restart, and doesn't execute the file by it self
Interesting behavior of winword.exe -> svchost.exe -> wmi -> powershell
Behavior visibility obtained by monitoring #RPC calls on the operating system
Recently uploaded, only 3/61 hits on VT, fake "Protected document" while executing malicious #MSI payload on the machine from remote server.
https://t.co/RNH70Kq7at
TPOT Honeypot platforms #tpotce can upload samples captured from the #adbhoney and #Dionaea Honeypots to the SNDBOX Platform @SNDBOXCOM with the SNDBOX-MultiFile-Uploader. Check it out at:
https://t.co/kxTbk8FiuF
Created a Light Python3 wrapper for the SNDBOX Rest API
@SNDBOXCOM the code will upload supported files, provide metadata details and search the SNDBOX database returning the raw response. Check it out at: https://t.co/NQwiWbUQju
New static feature: we have added a DOCUMENT PREVIEW tab, preview to document files & #OCR.
This opens many new feature possibilities to (A) enhance our detection, (B) #similarity search between known attacks, and (C) more information for researchers
https://t.co/u5a6pO7cbS