Evasive VBS with very low VT

Status
Not open for further replies.

Sandbox Breaker - DFIR

Level 12
Thread author
Verified
Top Poster
Well-known
Jan 6, 2022
538
1,723
1,069
Inside a sandbox.
1687975091634.png

1687974917035.png

Bypassed Check Point TE.
1687975005636.png

Caught by OpenTip Kaspersky

Caught by Intelix

Caught by Intezer
 

Attachments

  • 1687974954164.png
    1687974954164.png
    15.2 KB · Views: 300
View attachment 276688
View attachment 276685
Bypassed Check Point TE.
View attachment 276687
Caught by OpenTip Kaspersky

Caught by Intelix

Caught by Intezer
Checkpoint ONLY missed it cause it was in a zip. if you extract it and scan its detected with Heuristics
 
  • Like
Reactions: roger_m
I wanna see if Threat Emulation does anything, can u try to turn everything off besides threat emulation and see how that goes?

I also scanned it and was detected with Heursitics
 
Status
Not open for further replies.

You may also like...