Question How do I test large samples with anyrun?

General Security Discussions
48 Replies 5,318 Views
Help answer the author's question with clear explanations and useful steps.

Studynxx

Level 9
Verified
Well-known
They have a 10MB limit iirc. But what If I'm trying to test an entire program whose size is about 1,6GB? I know I'm supposed to test the installer because that's what drops the other files but still I'm unsure.
 
They have a 10MB limit iirc. But what If I'm trying to test an entire program whose size is about 1,6GB? I know I'm supposed to test the installer because that's what drops the other files but still I'm unsure.
The real malicious activity, if any, will be initiated by the installer. This is where the initial compromise happens, files are dropped, registry keys are modified, and network connections are established. Your best bet is to analyze the installer, not the full program. This is the "patient zero" of the infection chain.
 
They have a 10MB limit iirc. But what If I'm trying to test an entire program whose size is about 1,6GB? I know I'm supposed to test the installer because that's what drops the other files but still I'm unsure.
Unfortunately 1.6GB installer is impossible to be uploaded. One thing you can try is, you can unpack the installer, this doesn’t guarantee that malicious activity is not performed via dlls, side loading, or even the install script.

That’s one of the cloud sandboxes limitations, they can’t and won’t handle files almost 2GB installer size.

What’s the installer, where was it obtained from, who signed it?

If it’s one of these inflated malware samples, you can manually edit to remove the repetitive bytes.

If it’s something like Adobe software, download from the official websites only.
 
The real malicious activity, if any, will be initiated by the installer. This is where the initial compromise happens, files are dropped, registry keys are modified, and network connections are established. Your best bet is to analyze the installer, not the full program. This is the "patient zero" of the infection chain.
Unfortunately 1.6GB installer is impossible to be uploaded. One thing you can try is, you can unpack the installer, this doesn’t guarantee that malicious activity is not performed via dlls, side loading, or even the install script.

That’s one of the cloud sandboxes limitations, they can’t and won’t handle files almost 2GB installer size.

What’s the installer, where was it obtained from, who signed it?

If it’s one of these inflated malware samples, you can manually edit to remove the repetitive bytes.

If it’s something like Adobe software, download from the official websites only.
Understood. I have Kaspersky running on the VM. It's not detected anything. How high are the chances of the sample being clean then? I'm not seeing any VT hits in Process Explorer
 
Understood. I have Kaspersky running on the VM. It's not detected anything. How high are the chances of the sample being clean then? I'm not seeing any VT hits in Process Explorer
You’ll have to tell us more about the sample.
 
Here's the problem: if I only run the installer through any run, it cannot get the files the installer drops. I'm getting related errors inside the sandbox for this reason
Very weird, how did you even run the installer on Any.run, did you compress it? Cuz that (from 1.6GB to under 10mb) is a highly abnormal decompression ratio?
 
Very weird, how did you even run the installer on Any.run, did you compress it? Cuz that (from 1.6GB to under 10mb) is a highly abnormal decompression ratio?
No, I didn't compress it. Basically the installer needs all the files inside the folder to install. It's an "autoplay.exe"
 
Try Triage | Triage instead, their file limits are more generous
1GB, still exceeds, this one is almost double.
No, I didn't compress it. Basically the installer needs all the files inside the folder to install. It's an "autoplay.exe"
Ok, it’s some app from a torrent. Potentially see if you can compress to a GB to upload on triage. But these platforms are plagued with false positives as well. I would trust Kaspersky more than I would trust triage and similar.
 
1GB, still exceeds, this one is almost double.

Ok, it’s some app from a torrent. Potentially see if you can compress to a GB to upload on triage. But these platforms are plagued with false positives as well. I would trust Kaspersky more than I would trust triage and similar.
What platforms? Do you mean anyrun and triage?
 
Dang how come? That's unfortunate. Altho you're definitely right because I kid you not, I once ran a legit official installer.exe on VirusTotal, and there 5 clowns from triage and other sites saying it's malicious lmao
Yeah, for these platforms you will have to look carefully at the behaviour and connections to determine if it’s malware. It’s what they are designed for, they are not designed for a “quick win” in malware analysis.
Sometimes even a harmless PDF will be flagged.
 
I think no free web sandbox offers that size limit. Some Enterprise Sandbox or Malware Analysis Systems can do thou.

Another option is if you're really unsure and you got AV Subscription, submit it to the Labs. They will ask you to zip and password protect(Likely INFECTED) and they will test it for you. This is your rights if you are a paying customer.
 
You can always analyze the suspicious file by performing a static analysis using a tool like PEStudio "which can handle that size of file".

This approach is the safest because it allows you to examine the file's contents without executing it. PEStudio provides a wealth of information, from file hashes that can be used to query threat intelligence databases, to metadata that may reveal anomalies in the file's creation. The tool also exposes a list of imported functions, which can provide strong hints about the file's purpose, for instance, a file that imports network-related functions is likely designed to communicate externally. Furthermore, it extracts any hardcoded strings, which can be valuable for uncovering URLs or filenames, and measures entropy. This initial analysis is instrumental in building a profile of the sample's potential behavior and guides your subsequent observations.

After completing the static analysis, the next phase is a dynamic analysis. With your virtual machine still set up, download Wireshark then you can disconnect from the internet, use Process Explorer and Wireshark to monitor the file in real time. First, launch both tools, ensuring Wireshark is actively capturing traffic on the VM's network interface. Then, run the suspicious file. As it executes, closely observe Process Explorer for any new processes that appear, paying attention to their names and any child processes they might spawn. Simultaneously, monitor Wireshark for any attempted network connections. Even though the VM is offline and no packets can leave the system, the attempt to create network traffic is a key indicator of the sample's functionality. By combining the insights from both the static and dynamic analysis, you can achieve a comprehensive understanding of the sample's purpose, all while minimizing the risk to your system.
 
You can always analyze the suspicious file by performing a static analysis using a tool like PEStudio "which can handle that size of file".

This approach is the safest because it allows you to examine the file's contents without executing it. PEStudio provides a wealth of information, from file hashes that can be used to query threat intelligence databases, to metadata that may reveal anomalies in the file's creation. The tool also exposes a list of imported functions, which can provide strong hints about the file's purpose, for instance, a file that imports network-related functions is likely designed to communicate externally. Furthermore, it extracts any hardcoded strings, which can be valuable for uncovering URLs or filenames, and measures entropy. This initial analysis is instrumental in building a profile of the sample's potential behavior and guides your subsequent observations.

After completing the static analysis, the next phase is a dynamic analysis. With your virtual machine still set up, download Wireshark then you can disconnect from the internet, use Process Explorer and Wireshark to monitor the file in real time. First, launch both tools, ensuring Wireshark is actively capturing traffic on the VM's network interface. Then, run the suspicious file. As it executes, closely observe Process Explorer for any new processes that appear, paying attention to their names and any child processes they might spawn. Simultaneously, monitor Wireshark for any attempted network connections. Even though the VM is offline and no packets can leave the system, the attempt to create network traffic is a key indicator of the sample's functionality. By combining the insights from both the static and dynamic analysis, you can achieve a comprehensive understanding of the sample's purpose, all while minimizing the risk to your system.
Yes, but the inclusion of Virtual Machines (specially with artefacts not properly hidden) can throw malware off and it can deliver behaviour that’s not the same as what it just delivered on the real system.

Also, it is possible that it may remain silent until certain events/conditions are met (including time-based).

An emulation service wull usually detect attempts for evasions and will perform fast-forward emulation, ignoring sleeps and so on.

So that approach is still not perfect.
 
Yes, but the inclusion of Virtual Machines (specially with artefacts not properly hidden) can throw malware off and it can deliver behaviour that’s not the same as what it just delivered on the real system.

Also, it is possible that it may remain silent until certain events/conditions are met (including time-based).

An emulation service wull usually detect attempts for evasions and will perform fast-forward emulation, ignoring sleeps and so on.

So that approach is still not perfect.
Those same factors apply to those platforms as well, this was just an additional option and learning opportunity.
 
Those same factors apply to those platforms as well, this was just an additional option and learning opportunity.
They apply to anything where virtualisation is used, but when the virtual machine was created just now, it doesn’t have a lot of programmes, it doesn’t make any attempts to hide hardware-based characteristics like bios name, drivers, it doesn’t have any browser histories (or the history is from an hour ago)…. It’s even more suspicious to malware.

This works best on a mature virtual machine, there is the pafish project on GitHub that users can download to scan their VMs.
 
Just throw the software away. You have narrowed it down and suspect it already. What are you going to do when you DO find proof that it is malware - you throw it away. You are not going to file a case to the FBI to prosecute the bugger anyways. Or is this going to be the first dip in the pond and you are going to turn professional someday ? Continue on if this is going to be an educational trip.
 
Last edited:

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top