You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
76487-640-1464517-23259 // malwr.com sandbox
76487-341-0620571-22546 // From one of the virustotal sandboxes
It'd also be cool to check for the repeating patterns used by JoeSecurity as found in [2]
All the annotations above are what I've been able to find from searching the web, but as you can see their are many that I couldn't find any information on. [1] mentions that some of these are associated with GFI and Kaspersky, but I'm not sure which. I wonder if these lists are on some hacker forum somewhere, for instance, and if so, it'd be awesome if we could collect that info here
Some malware will look for ProductIds associated with commercial sandboxes and stop running if detected. For example, from [1]:
Although these checks are still common in malware, they are a bit dated (Anubis has shutdown, for instance). Is it worth adding a check for these?
[1] https://cofense.com/kutaki-malware-bypasses-gateways-steal-users-credentials/
The text was updated successfully, but these errors were encountered: