Buster Sandbox Analyzer

Discussion in 'other anti-malware software' started by Buster_BSA, Nov 29, 2009.

Thread Status:
Not open for further replies.
  1. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    The latest release is working great! I really like the features.
     
  2. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    I will release a new version soon with a few bugfixes.
     
  3. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    With the latest version of Sandboxie where 64-bit experimental is used, the malware I test don't behave properly. Sandboxie interferes the stuff the malware intends to do (I'm running without Drop-My-Rights). Hence, BSA won't register any malicious activity. This is not a glitch in BSA, but more than not, a bad thing about Sandboxie itself.

    I look forward to every new release. BSA is every malware-testers dream!
     
  4. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Released Buster Sandbox Analyzer 1.37.

    Changes:

    * Improved hiding feature
    * Updated BSA.DAT
    * Removed evaluation risk feature
    * Fixed several bugs

    Part of the improved hiding feature is the possibility of naming LOG_API.DLL with the file name you prefer.

    Evaluation risk was removed from malware analysis report because it was too misleading. Probably I will reintroduce the feature future in the near but having other format.
     
    Last edited: Jul 16, 2011
  5. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Hey Buster,

    On a side notice, Emsisoft & Ikarus report some of the files included in BSA as suspicious:

    Scan start: 2011-07-17 00:24:55

    D:\bsa\HideDriverGUI.exe detected: Trojan.Win32.Tool.HideProc.bz!A2
    D:\bsa\LOG_API.DLL detected: Win32.SuspectCrc!IK

    I have of course submitted them as false positives!

    Regards,

    Gabe
     
  6. guest

    guest Guest

    Thanks for the update, it's working fine here :)
     
  7. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Thank you very much!
     
  8. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Thanks for the feedback!
     
  9. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    I forgot to comment a new feature in version 1.37.

    * Added "Version Information" feature. This feature will include a header in reports with the version and date of creation of reports.
     
  10. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    The changes introduced in this new version are not visible, but they improve the quality of reports significantly.
     
  11. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Released Buster Sandbox Analyzer 1.38.

    Changes:

    + Added risk evaluation module
    + Added several improvements
    + Fixed several bugs
     
  12. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Cheers for the risk evaluation module! :) It gives a hint of what to do with the tested file (after manually checking what changes were made). Much appreciated.
     
  13. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    No problem, glad you like it.
     
  14. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Tzuk should make you co-developer... this tool would be so handy to have built-in into Sandboxie.
     
  15. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    tzuk helps me to improve BSA adding things I need. Right now I am waiting he has some free time to review a feature request I did. I want to add a new malicious behaviour that will help BSA to catch malwares that write to MBR or that write to sectors directly.
     
  16. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    I noticed a bug in version 1.38 and updated BSA package with the fix.

    People that downloaded the package should get it again.
     
  17. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    If anyone notices a "invalid integer value" error message, redownload the package.
     
  18. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Released Buster Sandbox Analyzer 1.39.

    Changes:

    + Fixed several bugs.
     
  19. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Released Buster Sandbox Analyzer 1.40.

    Changes:

    + Usability improvement in File Hash, File Scanner, File Signature and automatic analysis features: last used folder will be remembered
    + Usability improvement in File Hash, File Scanner and File Signature features: added drag and drop support
    + Added Exeinfo support to File Signature feature
    + Improved File Hash feature: all hashes can be checked at VirusTotal at once, VirusTotal reports can be saved to disk
     
  20. guest

    guest Guest

    Thanks for the update.
    Would be nice for future versions to have a guided way to install it.
     
  21. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    I will consider it.
     
  22. icr

    icr Registered Member

    Joined:
    Sep 6, 2008
    Posts:
    1,589
    Location:
    UK
    Thanks for the update ;)
     
  23. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Glad you like it.

    Nobody did that suggestions to improve the feature. I was reviewing the feature to add other things and I thought about them.

    If you have suggestions to improve that function or other ones, let me know.
     
  24. icr

    icr Registered Member

    Joined:
    Sep 6, 2008
    Posts:
    1,589
    Location:
    UK
    Well I normally did that manually in the past :D Well definitely save my time ;)
    Keep up the good work of developing such a good software application:thumb: :thumb:
     
  25. Buster_BSA

    Buster_BSA Registered Member

    Joined:
    Nov 29, 2009
    Posts:
    748
    Then I don´t understand why you didn´t make a feature request. o_O

    Thanks!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.