cuckoosandbox / cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system
http://www.cuckoosandbox.org
Other
5.56k stars 1.7k forks source link

Feature: Close started application during analysis #506

Closed theevilbit closed 9 years ago

theevilbit commented 9 years ago

Would it be possible to add a feature to the analyzer agent to close an application towards the end of the analysis? Run on close macros can bypass sandboxes, as they will never exit the started application and thus the malware will not start, as described here:

https://www.proofpoint.com/us/threat-insight/post/Run-on-Close-Macros-Try-to-Shut-the-Door-on-Sandboxes

botherder commented 9 years ago

This is actual a problem that needs to be investigated further. I'll open another ticket more specific to the sandbox evasion.

botherder commented 9 years ago

Moved to #509.