Malware Analysis Time to detect - Look at this sample

Sandbox Breaker - DFIR

Level 12
Thread author
Verified
Top Poster
Well-known
Jan 6, 2022
538
1,723
1,069
Inside a sandbox.
  • Like
Reactions: Zartarra and Kongo


Sample I uploaded last year. Still only 7/70 detection ratio. Reanalyzed today and they all have same verdicts. Why is this becoming my new normal haha. I'd love to hear what you all have to say to this.

It's a script :)
It's not uncommon for malware to have a low detection rate on antivirus engines, especially if it's a new or sophisticated piece of malware. This is why it's always important to analyze suspicious files using multiple tools and techniques.

In your case, the fact that the sample is a script might also contribute to the low detection rate. Some antivirus products may not have advanced capabilities to detect malicious behavior in scripts.

Furthermore, it's worth noting that the number of detections is not always an accurate indicator of a file's maliciousness. Some antivirus products may detect harmless files as malicious, and vice versa. It's important to review the analysis reports from different tools to better understand the nature of the file.

If you're concerned about the script's behavior, you can perform more in-depth analysis using dynamic analysis tools to observe its actions in a controlled environment.
 
  • Like
Reactions: roger_m