5 USER ENVIRONMENT AND INTERACTION DETECTION
As automated malware sandboxes get better at hiding themselves from evasive malware, malware authors must adapt. One tactic they use is to enumerate the user’s environment and the user’s interaction with it. As Chapter 4 noted, the everyday user’s setup has open browser tabs, many windows open and apps in use, and frequent mouse and keyboard interaction, making it quite different from the sandbox environment. An automated malware analysis sandbox is designed to boot up, detonate a malware sample, and then promptly shut down. It may not exhibit any normal user behaviors or other indicators that ...
Get Evasive Malware now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.