Dynamic Attachment Analysis and Sandboxing


Four Things to Look For

  1. Process Activity
    • what process are being spawned
    • what are the parent-child relationships
  2. Registry Activity
    • Registry changes
    • Persistence mechanisms
    • Writing or overwriting registry entries?
  3. Network Activity
    • What network connections are made
  4. File Activity
    • Dropping other files
    • Writing to disk
    • Modifying files

Tools

Hybrid Analysis

  1. Upload file for analysis
  2. Select a machine for sandbox
  3. Runtime Options;
    • Can choose simulated user behavior scripts
    • duration
    • custom commands
    • document password
      • etc.
  4. Generate Public Report
    • Anyone can access it
    • Do not submit sensitive info
  5. Analyze Report
    • Label whether malicious or not
    • Can contain CVE
    • Anti-Virus Results
      • Shows if flagged by AV
      • Static analysis
    • Falcon Sandbox Reports
      • Can see dynamic analysis in action
    • Incident Response
    • Indicators
    • File Details
    • Screenshots
      • screenshots taken of sandbox machine during execution
    • Hybrid Analysis
    • Network Analysis
      • See what connection requests were made
      • DNS Requests
      • Contacted Hosts
      • Contacted Countries
      • HTTP Traffic
      • Suricata Alerts
    • Extracted Strings
    • Extracted Files

Joe Sandbox

  • Requires business email account
  1. Upload file
  2. Select sandbox OS
  3. Can enable Live Interaction
    • Can interact with the sandbox
  4. Analyze with Joe Sandbox
    • Report is public
  5. Analyze Results
    • IOCs
    • Signatures
    • Classifications
    • Process Tree
    • Network Analysis
    • etc.

ANY.RUN

  1. Upload File/URL/Email
  2. Configure Settings
  3. Run Analysis
    • Public
  4. Analyze Report
    • IOCs
    • Network connections
    • Can click text report to save as PDF
    • Etc.