ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

VirusTotal launches 'Droidy' sandbox to detect malicious Android apps

mediumMalwareimportance 30

Indicators of compromiseAll →

TypeIndicatorContext
sha2563efbb1acdc52153dd61ddafd25d2fbf8f68924b76093c462414097fb827a38c2625bc89b5936b323/behavior https://www.virustotal.com/#/file/3efbb1acdc52153dd61ddafd25d2fbf8f68924b76093c462414097fb827a38c2/behavior https://www.virustotal.com/#/file/925f4f4cbc6ccbce
sha2565d26b7141f0d0f76a15ff7b5baf884139b1808ddca2eb8cb625bc89b5936b323ies of VirusTotal Droidy: https://www.virustotal.com/#/file/5d26b7141f0d0f76a15ff7b5baf884139b1808ddca2eb8cb625bc89b5936b323/behavior https://www.virustotal.com/#/file/3efbb1acdc52153d
sha256925f4f4cbc6ccbce10f33cd08a0201da507251854749546715f2a6dbcfba8044414097fb827a38c2/behavior https://www.virustotal.com/#/file/925f4f4cbc6ccbce10f33cd08a0201da507251854749546715f2a6dbcfba8044/behavior https://www.virustotal.com/#/file/cd7ee117b3bc9348
sha256cd7ee117b3bc93485c43717037f05ed01de08679cbad9d571ee43d8df0cd303115f2a6dbcfba8044/behavior https://www.virustotal.com/#/file/cd7ee117b3bc93485c43717037f05ed01de08679cbad9d571ee43d8df0cd3031/behavior How "VirusTotal Droidy" Is Better Than Older "Viru
Full article352 words · extracted from thehackernews.com · click to collapse

The Hacker NewsApr 05, 2018

One of the biggest and most popular multi-antivirus scanning engine service has today launched a new Android sandbox service, dubbed VirusTotal Droidy, to help security researchers detect malicious apps based on behavioral analysis.

VirusTotal, owned by Google, is a free online service that allows anyone to upload files to check them for viruses against dozens of antivirus engines simultaneously.

Android Sandbox performs both static and dynamic analysis to automatically detect suspicious applications by executing and monitoring applications in a simulated Android OS environment.

Behavioral reports for Android applications (APKs) is not new to VirusTotal, as the website already had service since 2013 that worked based on Cuckoo Sandbox, an open source automated malware analysis system.

Replacing this existing system, VirusTotal Droidy has been integrated in the context of the multi-sandbox project and can extract "juicy" details, such as:

  • Network communications and SMS-related activity
  • Java reflection calls
  • Filesystem interactions
  • SQLite database usage
  • Services started, stopped
  • Permissions checked
  • Registered receivers
  • Crypto-related activity

Here below you can check behavioral analysis reports of some malicious Android apps, showcasing new functionalities of VirusTotal Droidy:



How "VirusTotal Droidy" Is Better Than Older "VirusTotal Sandbox"

VirusTotal also shared another sample report generated using the older version of VirusTotal Sandbox. You can simply click select "VirusTotal Droidy" to see new report for the same sample and compare both technologies at the same time.

For many samples, VirusTotal also offers reports from multiple sandboxes, including Tencent HABO, a service independently developed by Chinese Antivirus firm Tencent.

"The richer the information that we generate for individual data set items, the greater the telescopic capabilities of VirusTotal," the company said. "This is how we manage to fill in the dots and quickly see all activity tied to certain resources that often show up in malware investigations."

Report generated using new VirusTotal Droidy Android sandbox technology also includes interactive data from other services such as VirusTotal Intelligence and VirusTotal Graph.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2018/04/virustotal-droidy-android-sandbox.html