A forum for reverse engineering, OS internals and malware analysis 

Search found 56 matches: Cuckoo Sandbox

Searched query: cuckoo sandbox

ignored: sandbox

 Go to advanced search

Re: Sandboxes (Discussion)

 by fonavozia ¦  Thu Mar 15, 2018 9:38 am ¦  Forum: Malware ¦  Topic: Sandboxes (Discussion) ¦  Replies: 25 ¦  Views: 28257

After the death of malwr.com (plain simple cuckoo sandbox without the hassle) I've switched to maldun (https://www.maldun.com/dashboard/). The only drawback it's in Chinese, but the links and css classes are pretty self-explanatory, so I've already got used to all its characters :)

Re: Shadow Security Scanner

 by Bogdan-Mihai ¦  Thu Sep 08, 2016 11:01 am ¦  Forum: General Discussion ¦  Topic: Shadow Security Scanner ¦  Replies: 4 ¦  Views: 10981

Good point. I have a Cuckoo with 3 diff VMs, I can run it in there, too. I`ll wait for your thoughts.

Re: Shadow Security Scanner

 by waffles2.0 ¦  Thu Sep 08, 2016 8:19 am ¦  Forum: General Discussion ¦  Topic: Shadow Security Scanner ¦  Replies: 4 ¦  Views: 10981

I shall take a look and run it in Cuckoo see if anything interesting pops up. I'll report back if there is anything interesting.

Re: VBoxAntiVMDetectHardened mitigation X64 only (22/07/16)

 by tizanidine ¦  Sat Aug 13, 2016 8:49 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757727

Hi guys, I just want to pitch in with my little contribution. I've been trying to harden my VirtualBox 5.1.2 instance that I run under cuckoo on Debian against detections. My guest is a Win10 x64 installation. It was a huge pain in the ass and pretty much took two days of trial and error ...

using one malware report to detect all from same family

 by enkidu ¦  Sat May 14, 2016 3:34 pm ¦  Forum: Malware ¦  Topic: using one malware report to detect all from same family ¦  Replies: 1 ¦  Views: 4132

... malwares (dynamic analysis) have similar behaviour (pattern). i have cuckoo sandbox and reports in malheur, json and maec formats. my question is: how can i use report ...

Re: Malware with heavy virtual machine and sandbox detection

 by EP_X0FF ¦  Mon Apr 25, 2016 11:45 am ¦  Forum: Malware ¦  Topic: Win32/Furtim ¦  Replies: 22 ¦  Views: 54439

... sample_execution mlwr_smpl.exe C:\agent\agent.pyw C:\sandbox\starter.exe c:\ipf\BDCore_U.dll C:\cwsandbox_manager C:\cwsandbox ... Analysis C:\iDEFENSE\SysAnalyzer c:\gnu\bin C:\SandCastle\tools C:\cuckoo\dll C:\MDS\WinDump.exe C:\tsl\Raptorclient.exe C:\guest_tools\start.bat ...

Re: VBoxAntiVMDetectHardened mitigation X64 only (27/01/16)

 by futex ¦  Mon Mar 14, 2016 4:07 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757727

Hi, I'm looking for a way to harden Cuckoo sandbox machines that are running on Ubuntu host using vbox. Is there any guide / documentation for hardening ...

Re: VBoxAntiVMDetectHardened mitigation X64 only (27/01/16)

 by EP_X0FF ¦  Mon Mar 14, 2016 4:02 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757727

Hi, I'm looking for a way to harden Cuckoo sandbox machines that are running on Ubuntu host using vbox. Is there any guide / documentation for hardening ...

Re: VBoxAntiVMDetectHardened mitigation X64 only (27/01/16)

 by idorosido ¦  Mon Feb 15, 2016 7:46 am ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757727

Hi,

I'm looking for a way to harden Cuckoo sandbox machines that are running on Ubuntu host using vbox.
Is there any guide / documentation for hardening win7 64bit vm on VBOX installed on Linux hypervisor ?

I want to get rid from "80ee:cafe" & "80ee:beef" device ids.

Thanks,

Re: VBoxAntiVMDetectHardened mitigation X64 only (07/01/16)

 by splinter_code ¦  Wed Jan 20, 2016 7:12 pm ¦  Forum: Tools/Software ¦  Topic: VBoxAntiVMDetectHardened mitigation X64 only ¦  Replies: 249 ¦  Views: 1757727

... including bullshit. * Pafish (Paranoid fish) * Some anti(debugger/VM/sandbox) tricks used by malware for the general public. [*] Windows version: ... name ... OK [*] cpuid Intel wrong value for processor name ... OK [-] Cuckoo detection [*] Looking in the TLS for the hooks information structure ...