Source |
Fortinet |
Identifiant |
455101 |
Date de publication |
2018-01-03 17:45:59 (vue: 2018-01-03 17:45:59) |
Titre |
Prevalent Threats Targeting Cuckoo Sandbox Detection and Our Mitigation |
Texte |
In this blog post, we will discuss the history of sandbox detection. We will then unveil the malware families that KTIS has observed from spear-phishing emails that attempt to bypass the user-mode API hook in order to evade sandbox detection. And finally, we will share the mitigation method we use to harden the Cuckoo sandbox against this bypass technique. |
Notes |
|
Envoyé |
Oui |
Condensat |
against api attempt blog bypass cuckoo detection discuss emails evade families finally from harden has history hook ktis malware method mitigation mode observed order phishing post prevalent sandbox share spear targeting technique then threats unveil use user will |
Tags |
|
Stories |
|
Move |
|