how to safely test malware?

Page 2 of 2 FirstFirst 12

  1. Posts : 112
    7
       #11

    Yes we have a malware tester over at Malwarebytes forum that only runs samples on the real system and images back.

    There are also rollback type apps such as RollbackRX, FD-ISR, AyeRecovery and Comodo Time Machine but I haven't really tried any of those.

    Another Shadow Defender/Returnil type app and free ATM is Wondershare Time Freeze.
    http://www.wondershare.com/blog/wond...otection-tool/
      My Computer


  2. Posts : 2,737
    Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
       #12

    malexous said:
    Some malware will detect that they are running in a sandbox or virtual machine and change their behaviour, therefore, best to test in a real environment.

    Most won't have a machine specifically for testing. As has been suggested, Shadow Defender or creating an image and reverting back to it after the testing is good.

    It's probably not a good idea to test on a machine that has sensitive data. Some malware will want to steal it and call home.
    Yes sir! This is my point exactly. Malware is no longer written by 15 year old kids, it is being written by sophisticated originations that have all the resources we have plus the resources of a large company. They know about VM or sandboxie etc., and they have many ways around it. Don't kid yourself in thinking you are perfectly safe because you are testing in a VM type, or sandbox type of environment.
      My Computer


  3. Posts : 112
    7
       #13

    And that's where you can use the hidedriver.sys within the Buster Sandbox Analyser to hide Sandboxie's processes but even then some malware still won't run.

    Why I prefer to use Sandboxie rather than a VM or virtualised real system is that it's way easier to find any droppers in the sandbox rather than searching system wide.

    If you know any ways that bypasses Sandboxie please elaborate over at Sandboxie's forum. You can only help an excellent security app get better.

      My Computer


  4. Posts : 2,737
    Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
       #14

    Jaxryley said:

    If you know any ways that bypasses Sandboxie please elaborate over at Sandboxie's forum. You can only help an excellent security app get better.
    Great point!
      My Computer


  5. Posts : 759
    W7-Enterprise + WS-2008 (Converted to Workstation)
       #15

    hi !

    Jaxryley said:
    Sandboxie, Returnil and VM's are used here.

    The main machine is always virtualised with Returnil and malware testings carried out in a sandbox or a VM.

    Buster Sandbox Analyser is used to monitor what the sample gets up to in the sandbox.

    And sometimes I run malware through Sandboxie in a VM which is virtualised by Returnil. LOL.

    Some malware can send out a call to reboot or shutdown the system. Returnil nor Shadow defender can't stop the call but Sandboxie contains the system call to reboot/shutdown.

    We all have our ways to do things and whatever suits you and you're comfortable with then use it.
    interesting, i´ve tested both Returnil & Sandboxie, and was thinking about enhancing the security by running both of them,
    first start Returnil & then run fx. Firefox in a sandbox.
    hmmm, going to try that combination...

    "Buster Sandbox Analyser" ?
    link ?

    do you mean this program ?
    Released Buster Sandbox Analyzer 1.23 | Offensive Computing
      My Computer


  6. Posts : 112
    7
       #16

    Here's the link to Buster Sandbox Analyzer over at Sanboxie's Forum.
    www.sandboxie.com :: View topic - Buster Sandbox Analyzer

    And another over at Wilders.
    Buster Sandbox Analyzer - Wilders Security Forums
      My Computer


  7. Posts : 759
    W7-Enterprise + WS-2008 (Converted to Workstation)
       #17

    thanks Jaxryley, that´s the program that is mentioned on the website i posted.
      My Computer


  8. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #18

    If you have no idea what you're doing while testing malware .... please stay off the Internet
      My Computer


  9. Posts : 422
    windows 7 64 bit
    Thread Starter
       #19

    i know what i am doing on the internet i just wanted to know how how other people test it.
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 04:13.
Find Us