Buster Sandbox Analyzer

Discussion in 'other anti-malware software' started by Buster_BSA, Nov 29, 2009.

Thread Status:
Not open for further replies.
  1. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
  2. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    Wow very nice feature :thumb:
    I will try.
     
  3. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
  4. Nizarawi

    Nizarawi Registered Member

    Joined:
    May 26, 2008
    Posts:
    137
    help

    beta 4
     

    Attached Files:

  5. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
  6. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Released Buster Sandbox Analyzer 1.32.

    Changes:

    + Added a feature to include av identifications from VirusTotal on reports
    + Improved “Automated Setup” feature
     
  7. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    With the inclusion of VirusTotal av detections, Buster Sandbox Analyzer becomes a very powerful malware analysis and detection tool.

    BSA combines the traditional pattern and heuristic detection (provided by VirusTotal´s av engines) with the malware behaviour analysis technology.

    From this combination we get a strong anti-malware tool.
     
  8. Nizarawi

    Nizarawi Registered Member

    Joined:
    May 26, 2008
    Posts:
    137
    Great update. Thank you

    work great here
     
  9. guest

    guest Guest

    I like VirusTotal addition. Thanks Buster
     
  10. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    You are welcome, guest and Nizarawi.
     
  11. Boyfriend

    Boyfriend Registered Member

    Joined:
    Jun 7, 2010
    Posts:
    1,070
    Location:
    Pakistan
    Nice new feature (VirusTotal). Thanks Buster_BSA :thumb:
     
  12. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    This is very welcome! Thanks a lot! Much appreciated!
     
  13. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    I wonder why nobody requested that feature ever.
     
  14. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Actually, I thought it might've been something to do with VT not allowing 3rd party applications to use their service other than their on VT-uploader. I've read their license agreement at their website now though and the do provide support for anyone to create an application for it (if I understand it correctly).

    Anyway, with your addon to Sandboxie and Sandboxie now fully supporting x64, I think SBIE is the ultimate testing tool for new files!
     
  15. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
  16. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Released Buster Sandbox Analyzer 1.33.

    Changes:

    + Added a feature to run BSA from command line in automatic mode
    + Added Exeinfo support
    + Added extra information of dropped files
    + Updated BSA.DAT
    + Updated LOG_API
    + Fixed a bug
     
  17. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    From version 1.33 BSA can run from command line in automatic mode. That means that no user iteraction is required to analyze a file or a group of files. You just need to specify the amount of time and the folder to process.

    The parameters to use are:

    "-m" or "-s" to define the time. "-m" is for minutes and "-s" for seconds. The min amount for minutes is 1 and the max 60. For seconds the min is 1 and the max 3600.

    "-f" to define the folder to process.

    Example: bsa.exe -s 30 -f c:\test

    In this example BSA will process for 30 seconds the files stored in test folder.
     
  18. s23

    s23 Registered Member

    Joined:
    Feb 22, 2009
    Posts:
    263
    Thank you for this great tool! Success.
     
  19. guest

    guest Guest

    Thanks for update. These are possible?

    Two or more files can be analysed at the same time? (with different sandboxes)

    Sometimes, Malware files dosen't work. Sometimes they terminate after working. For that kind of cases, can BSA finished analysis free from set-time and can I pass new file? (it will be ideal for corrupted and dead malwares.)
     
  20. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    First: I never coded any multithreaded application and I don´t have the time to do the research and the development that something like that requires.

    Second: I don´t follow you. Could you rephrase it, please?
     
  21. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Re-released BSA 1.33 package to fix a severe problem in LOG_API.
     
  22. guest

    guest Guest

    bsa.exe-m5
    (analysis will take time five minute)

    BSA run malware.exe
    After running 30 second, it terminates.
    And BSA waits for five miniute for new analysis.
    If BSA can determine the end of malware.exe, it does not need to run for 4.30 second. Time saver function.
     
  23. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Did you try the feature?
     
  24. guest

    guest Guest

  25. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,324
    may you add the feature export reghive registry in *.reg ?

    it would cool

    thanks
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.