Title
Case Study: Analysis and Mitigation of a Novel Sandbox-Evasion Technique
Abstract
Malware is one of the most popular cyber-attack methods in the digital world. According to the independent test company AV-TEST, 350,000 new malware samples are created every day. To analyze all samples by hand to discover whether they are malware does not scale, so antivirus companies automate the process e.g., using sandboxes where samples can be run, observed, and classified. Malware authors are aware of this fact, and try to evade detection. In this paper we describe one of such evasion technique: unprecedented, we discovered it while analyzing a ransomware sample. Analyzed in a Cuckoo Sandbox, the sample was able to avoid triggering malware indicators, thus scoring significantly below the minimum severity level. Here, we discuss what strategy the sample follows to evade the analysis, proposing practical defense methods to nullify, in our turn, the sample's furtive strategy.
Year
DOI
Venue
2019
10.1145/3360664.3360673
Proceedings of the Third Central European Cybersecurity Conference
Keywords
Field
DocType
detection, evasion, malware, ransomware, stateless
Sandbox (computer security),Computer security,Computer science
Conference
ISBN
Citations 
PageRank 
978-1-4503-7296-1
0
0.34
References 
Authors
0
3
Name
Order
Citations
PageRank
Ziya Alper Genç100.68
Gabriele Lenzini223736.20
Daniele Sgandurra361.80