Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
I think I have tried most or all of the sandboxes, can you name 2-3 that you think would give the best results? I would love to try them with our software if I have not.@danb depends on the sandbox, there are certain solutions which are quite accurate.
Sandboxing and static analysis are sometimes combined together, none of them can replace the other.
Anyway, let’s see the detection names.
This now looks like a scan engine.
It does look cool. It’s these little touches that make a difference.BTW, the malware name feature that @Trident suggested turned out really cool, here is how it looks...
Yes, but the email feature is a very long way off. More than anything, it is just an example of what we can do with this tech. But yeah, I did not think about GDPR, but that might be tricky... either way it would have to be a local model. I just hope the local model will have enough parameters to be useful. It certainly did not for the other analysis that we are doing... but AI is still young, so who knows what is going to happen.It does look cool. It’s these little touches that make a difference.
As to the sandboxes, Check Point, Palo Alto and Crowd Strike are the leaders on emulation, but I am not sure what APIs they offer (if they do offer).
I know Avira for sure offers emulation API but that’s gonna increase the cost of your product. You are soon gonna have to do editions.
In essence, look for emulation from an AV vendor if you wanna go down that path and don’t bother with generic sandboxes (like Cuckoo, AnyRun and so on). In addition, you can also go for third-party threat feeds if you wanna do a full-blown AV.
I like that you’re implementing anti-spam and scam features though yeah, with the GDPR this implementation will be more than tricky.
You’ll need to implement pre-scrubbing scripts.
Last but not least, maybe analyse pdf files for phishing as well.
Also, how will you reduce the performance impact of all these analysis? Even though everything happens on the cloud, I’m assuming the file is locked whilst in analysis…?
You can convert anything to text, there are all sorts of parsing libraries online. In this case not sure if it’s a good idea to normalise the text as some poor capitalisation can also be indicative of spam/scam, phishing and so on.Yeah, each document type is going to involve some preprocessing. Once we are able to convert it to text, it is super simple.
Yeah, but the ones for macros, for example, are not super straightforward... I think the other file types will be a lot easier.You can convert anything to text, there are all sorts of parsing libraries online. In this case not sure if it’s a good idea to normalise the text as some poor capitalisation can also be indicative of spam/scam, phishing and so on.
As a general UI practice, everything that takes a few seconds or more should have progress indicator.
I forgot to mention Sophos as well offers cloud sandbox on sophos.com/oem.Yeah, but the ones for macros, for example, are not super straightforward... I think the other file types will be a lot easier.
I wish Microsoft Defender had some kind of progress indicator... it drives me absolutely crazy when I have to wait 10-20 seconds for it finish analyzing a file.
For parsing of macros oletools has been the standard for quite some time and it can also extract macros in the cases where the project is password protected (not the whole file encrypted).Yeah, but the ones for macros, for example, are not super straightforward... I think the other file types will be a lot easier.
Thank you for the info... yeah, there is a lot more to parsing macros then I ever would have imagined. It is certainly doable, but it is not super straightforward.I forgot to mention Sophos as well offers cloud sandbox on sophos.com/oem.
They combine static analysis with dynamic one, and it seems to be very standard integration via Restful API but I am not sure of the costs.
For parsing of macros oletools has been the standard for quite some time and it can also extract macros in the cases where the project is password protected (not the whole file encrypted).
![]()
GitHub - decalage2/oletools: oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging. - decalage2/oletoolsgithub.com
But I am not sure what’s your policy on third-party code in your products.
If you are trying to build a parser from scratch, it will indeed take you some time and loads of trial and error.
This is how I envision prompts
No worries, the font there is Poppins.That is really cool, thank you, I appreciate your help!
So I was 98-99% finished, then it dawned on me the best way to handle the question I had in post #105.
After thinking about this for quite some time, I think the best way to handle this is to have a dropdown option so the user can choose one of three options for the user prompts.
1) Do not show prompts / show only info on the prompts but do not let the user allow new items. We need to come up with a great name for this option that is not too long.
2) Show only Block prompts
3) Show Block and Allow prompts
The default setting will be #2, which I think most people will use. But #1 will come in handy for happy clickers and #3 will be cool for advanced users who are wanting to be alerted for the items that Sirius is auto allowing. Essentially, if the 3rd option is selected and Sirius auto allows something, it will give you a quick "info" prompt saying "Hey, this was auto allowed". Then you can click on the details button to see the Sirius analysis.
So this is the best of both worlds... I think it is going to turn out great. The bad news is that it is going to take quite a bit of time to implement this new feature, but I am hoping it does not take over 4-5 days. This is by far the most difficult coding I have ever done... my brain hurts, but I think it is going to turn out super cool. I am also making sure it will be relatively easy to implement into our other products, so that takes some time too. Thank you guys!
I think psychologically-wise, users get along better with the traffic-light system. So maybe you can have both - brand and create a logo for Sirius LLM that is the colours you want it to be. And still maintain the notifications in the traffic light colour scheme.BTW, they are current red and blue, should we make them red and green instead? I mean, what are the international standards for these colors?
Definitely not red-green. I have a color-recognition disability for red-green and could distinguish red and blue much better.That is really cool, thank you, I appreciate your help!
BTW, they are current red and blue, should we make them red and green instead? I mean, what are the international standards for these colors?
This is great to know... thank you for the info!Definitely not red-green. I have a color-recognition disability for red-green and could distinguish red and blue much better.
Members who viewed this thread in the last 5 minutes