September 2024
Intermediate to advanced
488 pages
13h 29m
English

As automated malware sandboxes get better at hiding themselves from evasive malware, malware authors must adapt. One tactic they use is to enumerate the user’s environment and the user’s interaction with it. As Chapter 4 noted, the everyday user’s setup has open browser tabs, many windows open and apps in use, and frequent mouse and keyboard interaction, making it quite different from the sandbox environment. An automated malware analysis sandbox is designed to boot up, detonate a malware sample, and then promptly shut down. It may not exhibit any normal user behaviors or other indicators that ...