Dynamic Attachment Analysis and Sandboxing
Four Things to Look For
- Process Activity
- what process are being spawned
- what are the parent-child relationships
- Registry Activity
- Registry changes
- Persistence mechanisms
- Writing or overwriting registry entries?
- Network Activity
- What network connections are made
- File Activity
- Dropping other files
- Writing to disk
- Modifying files
Hybrid Analysis
- Upload file for analysis
- Select a machine for sandbox
- Runtime Options;
- Can choose simulated user behavior scripts
- duration
- custom commands
- document password
- Generate Public Report
- Anyone can access it
- Do not submit sensitive info
- Analyze Report
- Label whether malicious or not
- Can contain CVE
- Anti-Virus Results
- Shows if flagged by AV
- Static analysis
- Falcon Sandbox Reports
- Can see dynamic analysis in action
- Incident Response
- Indicators
- File Details
- Screenshots
- screenshots taken of sandbox machine during execution
- Hybrid Analysis
- Network Analysis
- See what connection requests were made
- DNS Requests
- Contacted Hosts
- Contacted Countries
- HTTP Traffic
- Suricata Alerts
- Extracted Strings
- Extracted Files
Joe Sandbox
- Requires business email account
- Upload file
- Select sandbox OS
- Can enable Live Interaction
- Can interact with the sandbox
- Analyze with Joe Sandbox
- Analyze Results
- IOCs
- Signatures
- Classifications
- Process Tree
- Network Analysis
- etc.
ANY.RUN
- Upload File/URL/Email
- Configure Settings
- Run Analysis
- Analyze Report
- IOCs
- Network connections
- Can click text report to save as PDF
- Etc.