A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #11072  by Buster_BSA
 Mon Jan 16, 2012 9:14 pm
Released Buster Sandbox Analyzer 1.49.

Changes:

+ Added support for XML reports
+ Added support for TLS hooks detection
+ Improved PDF Statistics
+ Updated LOG_API verbose versions to include FindFirst/NextFile support
+ Updated support for new VirusTotal web service
+ Fixed several bugs
 #11429  by Mr.Bojangles
 Sat Feb 04, 2012 1:33 pm
Code: Select all
--regdiff
user\current_classes\*\shell\sandbox = deleted registry key
OpenProcess(c:\users\user\desktop\sandboxie 4.62+bsa 1.49\bsa\bsa.exe) [c:\windows\syswow64\rundll32.exe]
OpenProcess(c:\program files\sandboxie\sbiectrl.exe) [c:\windows\syswow64\rundll32.exe]
maybe omit that and other engine notices? so it doesn't look like antis?

EDIT: The second two might actually be antis..
 #11435  by Buster_BSA
 Sat Feb 04, 2012 8:17 pm
Mr.Bojangles wrote:
Code: Select all
--regdiff
user\current_classes\*\shell\sandbox = deleted registry key
OpenProcess(c:\users\user\desktop\sandboxie 4.62+bsa 1.49\bsa\bsa.exe) [c:\windows\syswow64\rundll32.exe]
OpenProcess(c:\program files\sandboxie\sbiectrl.exe) [c:\windows\syswow64\rundll32.exe]
maybe omit that and other engine notices? so it doesn't look like antis?

EDIT: The second two might actually be antis..
You have the exclusion lists to avoid showing that kind of stuff.
 #12004  by Buster_BSA
 Tue Mar 06, 2012 7:18 pm
Released Buster Sandbox Analyzer 1.51.

Changes:

+ Added a custom driver to hide Sandboxie´s processes
+ Removed Hide Driver from package
+ Included new malware behaviour
+ Added File Renamer feature to utilities section
+ Updated LOG_API
 #12088  by Mr.Bojangles
 Tue Mar 13, 2012 7:53 am
When I finish my current contract I'll make another tool that checks for existence. I haven't looked at anything yet though. I also only use 64bit windows. The additions are nice.
 #12092  by Buster_BSA
 Tue Mar 13, 2012 9:36 am
Mr.Bojangles wrote:When I finish my current contract I'll make another tool that checks for existence. I haven't looked at anything yet though. I also only use 64bit windows. The additions are nice.
I would say I fixed Ldr->HashLinks detection some time ago. It will be nice if you can check if it´s really fixed.

Thanks!
 #12336  by Buster_BSA
 Sun Mar 25, 2012 1:29 pm
Released Buster Sandbox Analyzer 1.52.

Changes:

+ Added support for HTML reports
+ Added a feature to remove sandbox folder contents automatically in manual mode
+ Included new malware behaviour
+ Updated LOG_API
+ Fixed several bugs
  • 1
  • 18
  • 19
  • 20
  • 21
  • 22
  • 32