Sandboxie Terminated Ruskie Ransomware

Nico@FMA

Level 27
Verified
May 11, 2013
1,687
Where are they? Whats the name of the malware that you know that kills Sandboxie? Do you know anyone that had their sandbox (SBIE only, don't care about any other sandbox) bypassed?

Bo

Umbra Virus :p

http://www.wilderssecurity.com/showthread.php?t=350960

http://labs.bromium.com/2013/07/23/application-sandboxes-a-pen-testers-perspective/

TypeA sandboxes prevented certain ‘out-of-the-box’ exploits from widely used frameworks such as
Metasploit and isolated the threats as long as these are not sophisticated or targeted.
Type B sandboxes provide some security benefits against attacks exploiting vulnerabilities to break out of
the sandboxed environment.
It has been proved by a few recent strains of malware that it is possible to
break out of the sandboxed process, but exploitation is not as trivial as it used to be without the
sandbox.

Lesson: Sandboxie is a good tool for sandboxing programs that do not come with their own built-in sandbox, as long as the threats are not sophisticated or targeted.
Lesson: All it takes is an OS vulnerability to bypass a ANY sandbox (Including Sandboxie)

Granted Sandboxie is GREAT and i would advise it anytime i can, but facts are facts Sandboxie does not protect you.
It only increases the standards and quality that malware needs to gain entree.
 
  • Like
Reactions: Littlebits
D

Deleted member 178

I remembered one malware that bypassed SB in a specific configuration but the flaw was patched since
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top