Sandbox
16 min
sandbox and file analysis is an isolated, in platform environment for safely inspecting suspicious files and urls it is available as an add on to the cti module when you submit a file or url, it is analyzed inside a private virtual machine flare generates an analysis report covering execution behavior, process activity, file system changes, network activity, evasion techniques, extracted iocs, and a mitre att\&ck mapping the sandbox is powered by vmray and uses hypervisor based analysis key features in platform virtual machine files and urls are analyzed inside an isolated vm within flare no risk to corporate machines no need to export files to an external service the vm is spun up per submission and discarded after analysis automated analysis report each submission produces a structured report covering, execution behavior, process activity, file system changes, network activity (dns requests, http calls, c2 connections), evasion techniques attempted, and mitre att\&ck mapping of observed behaviors ioc extraction the analysis report automatically extracts network artifacts from the detonation c2 domains, dns requests, contacted urls, and file hashes these can be pushed into feeds for distribution to your siem, edr, or firewall — from sandbox submission to active blocking, without manual steps evasion resistant analysis vmray's hypervisor sits beneath the operating system the malware runs in an environment with, no monitoring hooks to detect, no agents inside the os, no virtual machine fingerprints to identify the malware cannot tell it is being analyzed, so it behaves naturally this is why the sandbox catches samples that hook based alternatives miss url analysis complete behavioral analysis of url submissions, covering phishing pages and credential harvesters with the same depth as file based malware private by design submissions are not shared with the broader community, vmray's research team, other flare customers, any external partner results are visible only to the submitting tenant access to this feature requires an add on please reach out to your csm for more information using the sandbox click through the following product tour to learn how to use the sandbox submit a file or url navigate to the sandbox page from the left navigation menu click analyze file or url, then upload a file or enter a url to analyze enter a file name and provide a password if the file is password protected choose an analysis mode interactive analysis analyze the file or url in a safe, isolated environment this option boots up a virtual machine that can be interacted with directly, which is useful for evaluating the specific actions a file takes when executed the virtual machine is permanently deleted after the session, so the file can be safely executed even if it performs malicious operations static analysis runs in the background and does not allow interaction with the file the sandbox does not currently support browsing onion links by default, they are labeled as suspicious the maximum supported file size is 680 mb review the analysis report submitted files and urls appear in the submissions list along with their type, upload date, size, and who submitted them once analysis is complete, the verdict column updates to show the result, such as clean click on a submission to open its full report, which presents findings organized by type execution behavior, network activity, iocs, and mitre att\&ck mappings severity ratings help prioritize what to act on first operationalize extracted iocs iocs extracted from the report, such as c2 domains, hashes, and network artifacts, can be pushed into feeds and applied to the detection stack this closes the loop from submission to active blocking pivot to the intelligence browser if the analysis surfaces an actor, malware family, or domain worth investigating further, pivot to the intelligence browser to pull the full entity profile, attribution, and relationship context analyzing stealer logs files discovered in stealer logs can be sent directly to the sandbox for analysis without needing to download them first navigate to the tenant feed from the events page click on an event, such as an infected device on stealer logs, to view its details go to the content tab click downloads, then select interact in sandbox select interact in sandbox as the analysis mode the zip file is sent to the sandbox automatically, and interactive analysis begins in an isolated virtual machine this makes it possible to investigate malware discovered inside a stealer log without leaving flare or exposing local infrastructure to risk once inside the sandbox, a browser window opens in the virtual machine and the file is downloaded automatically note keep the browser window open for the length of the session go to the downloads folder in the virtual machine and extract the zip file to investigate it once the investigation is complete, close the virtual machine analysis results after a file/url is submitted, the analysis then processes in the background to generate a report, which can take up to 10 minutes when it completes, the verdict for the file appears in the list next to the file/url name click on a file to view details of the analysis here you can review the verdict, any matched yara rules, mitre ttps, and more threat indicators threat indicators are behavioral patterns and rules flagged during analysis that point to possible malicious intent they are distinct from iocs, which are network artifacts like domains and hashes, rather than behavior in vmray, these are referred to as vtis (vmray threat identifiers) each indicator is scored on a five point scale the scale is not cumulative or linear, and a higher scoring indicator carries far more weight than several lower scoring ones combined for example, one score of 4 out of 5 is enough to automatically flag a sample as malicious, while three scores of 2 out of 5 would only be considered suspicious see the vmray threat identifier (vti) scoring system https //www vmray com/explained the vmray threat identifier vti scoring system/ for more information artifacts artifacts are pieces of forensic data observed during an analysis they can include files, urls, ips, processes, and registry entries, among other items not every artifact is malicious or cause for concern, since each one represents just a piece of the overall picture iocs are a subset of artifacts, for example, one malicious artifact or several suspicious artifacts together in flare, artifacts are extracted from dynamic analyses and displayed in the artifacts tab of the submission drawer each row can be expanded to see additional information about the artifact see indicators of compromise (iocs) and artifacts what’s the difference? https //www vmray com/indicators of compromise artifacts whats the difference/ for more information screenshots the screenshots tab shows the same screenshots that appear in the dynamic report, presented in a larger and clearer view screenshots are taken automatically by vmray during analysis, so the timing and content of each screenshot cannot be adjusted or made more specific original report this is the pdf report generated by vmray to download the report, use the three dot menu the sandbox provides two reports sample report a streamlined report showing the verdict and selected iocs analysis report a detailed report covering the processes, registry keys, websites, and other activity associated with the sample types of indicators of compromise flare's sandbox can return the following types of indicators of compromise (ioc) f iles f ilenames d omains emails and e mail addresses urls ips p rocesses m utexes r egistry entries (including registry key types if available) to download the associated ioc file expand the menu on the right of each entry, and download iocs as csv this will return the iocs in sha256 using api to upload files you can use flare's api to upload files for sandbox analysis, making it possible to add files programmatically as part of existing workflows files uploaded through the api appear in the uploads tab, which sits alongside the existing submissions tab for more information on uploading files to the sandbox, see our api documentation https //api docs flare io/api reference/v4/endpoints/create presigned upload url from the uploads tab, click analyze to investigate the file in the sandbox or run an automated background analysis uploading a file through the api does not trigger analysis automatically to analyze several files at once, select multiple files and click analyze in the background interactive analysis is limited to one file at a time, so bulk analysis must use the background option choose one file at a time for interactive analysis faqs what file types does the sandbox support? the sandbox supports the following files types sample type generic category target environment typical extensions supported version apple script macos scripts macos applescript, command, osascript, scpt archive static analysis with recursive dynamic detonations zip, 7z, tar, cab, rar, wim cfb file windows cfb custom windows various email (eml) email static analysis with recursive dynamic detonations eml email (msg) email static analysis with recursive dynamic detonations msg excel document microsoft office document windows xls, xlsx, xlsm, xlt, xltx, xltm, xltx, xlb, xlsb, iqy, slk, xml ms office >= 2007 html application html application windows hta13 html application (shell link) html application windows lnk3 html document html document windows htm, html iso disk images11 windows iso jscript windows javascript file windows js, jse jscript (shell link) shell link windows js, jse java archive java file windows, macos jar java class java file windows, macos class linux elf executable (x86 64) elf files linux elf, axf, bin, o, prx, puff, ko, mod, so macos app macos mach o macos app (must be submitted in a zip) macos dmg disk images11 macos dmg macos executable macos mach o macos none macos pkg macos pkg mhtml document html documents windows mht, mhtml microsoft access database microsoft office documents windows accdb, adn, accdr, accdt, accda, mdw, accde, ade, mdb, mda ms office >= 2007 microsoft onenote document microsoft office documents static analysis with recursive dynamic detonations one ms office >= 2010 microsoft project document microsoft office documents windows mpp2,4 ms office >= 2007 microsoft publisher document microsoft office documents windows pub, puz ms office >= 2007 microsoft visio document microsoft office documents windows vsd, vtx, vsdx, vsdm, vssx, vssm, vstx, vstm, vss, vsw ms office >= 2007 msi setup windows msi pdf document windows pdf adobe reader >= 6, up to and including dc powershell script powershell scripts windows ps1 powershell script (shell link) powershell scripts windows lnk3 powerpoint document microsoft office documents windows ppt, pptx, pptm, pot, potx, potm, ppa, ppam, pps, ppsm, ppsx ms office >= 2007 python script macos scripts macos py, command rtf document microsoft office documents windows rtf ms office >= 2007 shell script macos scripts macos sh, bash, zsh, command, csh, ksh, tclsh, tcsh svg svg image windows svg udf disk images11 windows udf unknown static analysis various url windows url vbscript windows script files windows vbs, vbe vbscript (shell link) shell link windows vbs, vbe url windows url windows batch file windows batch file windows bat, cmd windows batch file (shell link) windows batch file windows lnk3 windows dll (x86 32) windows pe (x86 32) windows dll windows dll (x86 64) windows pe (x86 64) windows dll windows driver (x86 32) windows pe (x86 32) windows sys windows driver (x86 64) windows pe (x86 64) windows sys windows exe (shell link) windows pe (x86) windows lnk3 windows exe (x86 32) windows pe (x86 32) windows lnk3 windows exe (x86 64) windows pe (x86 64) windows exe, scr windows help file windows chm windows installer patch windows msp7 windows script file windows script files windows wsf, wsc, ws, sct12 windows script file (shell link) shell link windows wsf, wsc, ws, sct12 word document microsoft office documents windows doc, docx, docm, dot, dotx, dotm, xml ms office >= 2007 is the sandbox included by default in the cti module? no, the sandbox is available as an add on to the cti module contact your customer success manager for more details