• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • Technique
  • Talking about sandbox
  • Technique

Talking about sandbox

Ddos May 31, 2017 5 minutes read
ssSandbox

In the past decade or so, the analysis of malware sandbox escape technology has become a silver bullet against high-level persistent threats, although this technology Become more and more popular, but malware developers seem to have found a static analysis based on the method (such as encryption , confusion and anti-reverse protection and other technologies) to avoid the traditional anti-virus security tool detection. Therefore, the analysis and research on the malware sandbox escape technology has become the last line of defense against our high-level persistent threats.

This series of articles mainly describes the current use of malicious software sandbox escape technology, the series points up and down, and will be a detailed analysis of the current three categories of mainstream sandbox escape technology.

Sandbox technology

In fact, the sandbox is a virtual system environment similar to the shadow system , it has a deeper level than the host virtual machine system kernel level technology. It can take over the function of malware to call interface or function behavior, and confirm the virus behavior after the implementation of the rollback mechanism, and let the system to maintain a clean state. It can be used to analyze and test programs that are untrustworthy, destructive, or unable to determine their true intent, and that all changes in the sandbox do not have any effect on the host operating system. Generally speaking, people who use this technology are generally in the field of computer information security professional and technical personnel, especially the anti-virus industry.

The working mechanism of the sandbox is very simple: how to determine whether a document is a malicious document? The sandbox will observe the behavior of the document in a controlled environment, and then judge it based on the analysis of the document Whether it has malicious behavior. The sandbox allows malware to perform all of its malicious functions in a controlled environment and record malicious behavior. After a period of observation, the analysis terminates and the sandbox treats the analysis as a typical malware Behavior mode to scan and detect this malware. Because the sandbox is no longer based on signatures to detect malware, it can even detect certain targeted or previously unwanted malware.

Obviously, behavior-based malware detection technology will only work if the observed file actually performs its malicious behavior in its analysis. If the target does not perform malicious behavior during the analysis, the sandbox will think that the file is friendly. Malware developers will continue to seek more innovative ways to hide the real behavior of malicious software, and to avoid sandbox detection. Here we divide these methods into the following three categories:

1. Sandbox detection: detection of the existence of sandbox (in the detection process only show friendly behavior);

2. Use sandbox vulnerability : the use of sandbox technology or the target environment in the presence of security flaws;

3. Context-Aware-based malware: the time / event / environment to judge, and in the sandbox analysis process will not be exposed to malicious behavior;

Sandbox detection

First of all, the first method of detecting sandboxes is to distinguish the nuances between the sandbox environment and the real target system. If a sandbox is detected, there are usually two ways to deal with malware: to immediately terminate the malicious behavior; only show friendly behavior, without performing malicious operations. We give an example here [the details of the light I], this sample has the following two characteristics:

1. Try to use the test to determine whether the current operating environment is a virtual machine (VM);

2. Detect whether the current environment has a sandbox application running (for example, Sandboxie)

 

We can learn from the details provided by the VMRay Threat Identification Service (VTI) that the VMRay discovery target will attempt to perform sandbox detection and mark this behavior as “highly suspicious”.

Use sandbox loopholes

The second approach is to use the underlying sandbox technology or target system environment in the security flaws to directly attack. For example, we recently found that there are a lot of malicious software use within Microsoft COM components , because most of the sandbox analysis of this sample can not be correct. Another kind of malware will confuse the file format and type, and let the sandbox can not handle such files properly. For example, an attacker could have a malicious file that exceeds the maximum file size that the sandbox can support, and the sandbox will not be able to parse such files.

We give you an example of “I’m getting it,” the malware will try to avoid using the API to avoid sandbox detection, and this method can be used to effectively avoid those based on the driver and function hook sandbox analyzer The But VMRay does not use the hook function, so this malicious software to avoid the sandbox detection attempt was detected and recorded:

 

Context-aware software (Context-Aware)

The third type of method used by malware does not actually attempt to detect or attack the sandbox, which takes advantage of the inherent flaws inherent in this automation system. Because most security detection environments and sandbox analysis systems do not take much time to analyze certain special malware, this malware can only avoid delays in malicious Payload execution time to effectively avoid sandbox detection. In addition to this time-based triggering condition, malware can also use events that typically do not occur in sandboxed environments, such as system reboots and user interactions. It should be noted that some malicious software will search the target device in some special tools, such as an application and localization settings, etc., interested in this part of the students can refer to this article.

In this sample analysis results, we can see that, in addition to trying to detect the virtual machine environment, this malware sample will also be through the installation of scripts and applications to achieve persistent infection:

Share this article:

Facebook Post LinkedIn Telegram

No related posts.

Tags: sandbox

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
  • CVE-2026-9435CVSS 9.8
    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9434CVSS 9.8
    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is...
  • CVE-2026-9433CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-2651CVSS 9.0
    A vulnerability in MLflow versions
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.