Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #51  
Old January 28th, 2010, 09:21 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Released Buster Sandox Analyzer 1.09.

Change list:

Added File Signatures feature
Updated LOG_API library

File Signatures provides information about the packer, if any, used to compress a file or the compiler used to build it.
  #52  
Old February 1st, 2010, 08:47 PM
Cadillakin Cadillakin is offline
Infrequent Poster
 
Join Date: May 2007
Posts: 18
Default Re: Buster Sandbox Analyzer

A big thank you to Buster for this analyzer..

I was shopping on Usenet for some tax software... I found it and ran it in the sandbox.. As is my practice, I explored the installed files. Everything worked well.. No obvious signs of infection. No writing to windows.. No start/run entries... No files created in temp folders. But I still wasn't satisfied. I used Buster's program and reran the install...

The program logs were literally laced with created events, dns queries to Russia.. and many hidden processes.. Needless to say, I kept it in the sandbox. What's most interesting to me is that there were many users commenting on this app in Newzbin that their scanners showed it clean... There are perhaps hundreds of users with the finest AV apps money can buy.. and they downloaded, installed and asserted it was clean.

It seems some of the bad guys aren't laying obvious eggs for the scanners to discover...
  #53  
Old February 1st, 2010, 09:09 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,360
Default Re: Buster Sandbox Analyzer

Quote:
I was shopping on Usenet
The Usenet is not a good place to shop. It's way too easy to acquire unwanted results there.
  #54  
Old February 4th, 2010, 09:14 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Buster Sandbox Analyzer 1.10 has been released.

As usual it can be downloaded from http://bsa.qnea.de

Last additions: File Hash, File Strings and some other stuff.

New features will help malware analyzers in their work.
  #55  
Old February 8th, 2010, 10:53 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Buster Sandbox Analyzer

Haven't commented on Buster Sandbox Analyzer as yet and all I can say is brilliant. Thanks Buster.
  #56  
Old February 9th, 2010, 09:28 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Thank you very much for your kind comment, Franklin!
  #57  
Old February 9th, 2010, 09:34 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Quote:
Originally Posted by Meriadoc
Very easy to use, will you add your own monitors - a sniffer...servers, DNS requests, process analyser.

A sniffer was included in version 1.08.

It checks for DNS requests, it captures FTP´s login/passwords, you can view packet data, etc.

I hope the feature fullfilled your needs. If not just let me know your throughts.

Regards.
  #58  
Old February 9th, 2010, 09:35 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Released Buster Sandbox Analyzer 1.11.

Change list:

Added File Hex Editor.


Version 1.11 includes a built-in hex editor.
  #59  
Old February 12th, 2010, 06:48 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Released Buster Sandbox Analyzer 1.12.

Change list:

Added File Scanner.


Version 1.12 includes a feature to submit files to VirusTotal to be scanned.
  #60  
Old February 12th, 2010, 07:09 PM
xXDarkStalkerxX xXDarkStalkerxX is offline
Frequent Poster
 
Join Date: Nov 2008
Posts: 273
Default Re: Buster Sandbox Analyzer

Amazing software , thanks Buster.
Does it works in x64?
  #61  
Old February 13th, 2010, 07:14 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Quote:
Originally Posted by xXDarkStalkerxX
Amazing software , thanks Buster.
Does it works in x64?

You´re welcome!

Works in x64? Good question!

I don´t know because I only have x86 machines, but I guess it will not be fully supported because I must make a x64 version of LOG_API. Maybe the rest is working fine, but as I say, don´t know for sure.

I´ll ask someone with a x64 system to test it for me and I´ll be back to you as soon as I have a reply, ok?
  #62  
Old February 14th, 2010, 01:52 PM
xXDarkStalkerxX xXDarkStalkerxX is offline
Frequent Poster
 
Join Date: Nov 2008
Posts: 273
Default Re: Buster Sandbox Analyzer

Quote:
Originally Posted by Buster_BSA
You´re welcome!

Works in x64? Good question!

I don´t know because I only have x86 machines, but I guess it will not be fully supported because I must make a x64 version of LOG_API. Maybe the rest is working fine, but as I say, don´t know for sure.

I´ll ask someone with a x64 system to test it for me and I´ll be back to you as soon as I have a reply, ok?

Ok !
  #63  
Old February 16th, 2010, 03:27 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

nick s, from Sandboxie´s forum, has been so nice to test BSA in a x64 system. He tells me BSA works fine in the platform.

There are only two things not working in 64-bit, but I was expecting that: LOG_API.DLL and the driver to hide Sandboxie.

That two misses mean next things:

* BSA will miss some functionalities to detect malware behaviour

* Sandboxie can not be hidden


A 64-bit version of the DLL may be coded but it´s not a trivial task, at least for me. If someone has the knowledge to make the conversion I would send him the source code of LOG_API.
  #64  
Old February 18th, 2010, 12:20 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Good news. Next Buster Sandbox Analyzer will contain an updated version of LOG_API library.

With the new version will be possible to analyze properly 32-bit malwares under a x64 system.
  #65  
Old February 25th, 2010, 11:48 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Released Buster Sandbox Analyzer 1.13.

Change list:

Added Process Explorer
Fixed bugs in Buster Sandbox Analyzer and LOG_API library
  #66  
Old February 25th, 2010, 11:52 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

The LOG_API library contained in version 1.13 works fine with Sandboxie x64, this means Buster Sandbox Analyzer will work properly in 64 bits systems.

The limitations under 64 bits systems are:

* The driver to hide processes will not work therefore Sandboxie is "visible" to malwares.

* LOG_API library works with 32 bits malwares, not with 64 bits. At the moment this doesn´t represent a problem because there are no 64 bits malwares.
  #67  
Old February 26th, 2010, 11:13 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Meriadoc: In version 1.13 I included "Process Explorer", a process viewer, dumper, ...

You had asked a process analyzer. What I included, is what you had on mind? If not, what could be added?
  #68  
Old March 8th, 2010, 08:24 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Released Buster Sandbox Analyzer 1.15:

Change list:

Added Memory Explorer feature
Updated BSA.DAT
Updated LOG_API library
Updated Buster Sandbox Analyzer
Fixed a bug in Buster Sandbox Analyzer
  #69  
Old March 8th, 2010, 08:25 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

There is a new URL to reach Buster Sandbox Analyzer web site:

http://bsa.sandboxie.info

I think that´s easier to remember than bsa.qnea.de.
  #70  
Old March 8th, 2010, 08:44 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Buster Sandbox Analyzer

With the additions it must be time to have another look at BSA.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #71  
Old March 11th, 2010, 01:33 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Meriadoc: Yes, it would be a good time for a new review.

I will release BSA 1.16 soon and it will contain the last feature I had planned to include.

Next versions will be more spaced in time and will fix bugs mainly.

I feel like I released first version of BSA a long time ago, but it was just four months since first release.
  #72  
Old March 12th, 2010, 04:09 PM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,201
Default Re: Buster Sandbox Analyzer

Quote:
Originally Posted by Buster_BSA
Meriadoc: Yes, it would be a good time for a new review.

I will release BSA 1.16 soon and it will contain the last feature I had planned to include.

Next versions will be more spaced in time and will fix bugs mainly.

I feel like I released first version of BSA a long time ago, but it was just four months since first release.

What's will be new in 1.16?
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #73  
Old March 12th, 2010, 07:49 PM
apathy's Avatar
apathy apathy is offline
Frequent Poster
 
Join Date: Dec 2004
Location: 9th Circle of Hell(Florida)
Posts: 366
Default Re: Buster Sandbox Analyzer

BSA is a great addon for Sandboxie.

I ran some 0day malware and it tracked everything.
I'd like to see some sort of hook into Sandboxie so I can start BSA with a right click on Sandboxie. I saw something like that in BSA but it didn't work for me.

Excellent application.
__________________
Setup For My Lenovo Ideapad Z575 12992KU
OS: Opensuse 12.3(KDE)

Spideroak | Nvpy | syncBackup(Rsync) | AirVPN | Glippy | Clementine | Thunderbird | Chromium w/ Vimium | Autokey | LFTP
  #74  
Old March 13th, 2010, 09:58 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Quote:
Originally Posted by lordraiden
What's will be new in 1.16?

Maybe you know Sandboxie stores the changes done to Windows registry by sandboxed applications in a file named "RegHive"

In 1.16 I will add "Reg Hive Explorer", a feature to visualize the contents of Sandboxie RegHive files.

There are other reghive viewers but this one will be the only one in the world specifically designed for Sandboxie.
  #75  
Old March 14th, 2010, 12:57 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Buster Sandbox Analyzer

Quote:
Originally Posted by apathy
BSA is a great addon for Sandboxie.

I ran some 0day malware and it tracked everything.
I'd like to see some sort of hook into Sandboxie so I can start BSA with a right click on Sandboxie. I saw something like that in BSA but it didn't work for me.

Excellent application.

Thanks for the kind words!

Do you mean you tried "Options -> Windows Shell Integration -> Add right-click ..." and that it didn´t work?
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:15 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums