ANY.RUN monthly updates: New Detection Rules, Increased Threat Coverage, and More
DUBAI, UAE, July 5, 2023/EINPresswire.com/ -- ANY.RUN, a cloud interactive sandbox for malware analysis, has released a Monthly Updates: New Detection Rules, Increased Threat Coverage in their blog.
๐๐ซ๐จ๐๐ฎ๐๐ญ ๐ฎ๐ฉ๐๐๐ญ๐๐ฌ
1. ๐๐๐ฌ๐ข๐๐๐ง๐ญ๐ข๐๐ฅ ๐๐ซ๐จ๐ฑ๐ฒ. Users can now assign a home userโs IP to virtual machines and change the location, making it easier to work with geo-targeted samples and evade detection.
2. ๐๐ฉ๐๐๐ญ๐๐ ๐๐๐๐๐ฎ๐ฅ๐ญ ๐๐ซ๐จ๐ฐ๐ฌ๐๐ซ๐ฌ. On Windows 10 and 11 machines, ANY.RUN changed the default web browser to Edge, instead of the previously used Internet Explorer.
3. ๐๐จ๐ฐ๐ง๐ฅ๐จ๐๐๐๐๐ฅ๐ ๐ฆ๐๐ฆ๐จ๐ซ๐ฒ ๐๐ฎ๐ฆ๐ฉ๐ฌ. Users can now download memory dumps and analyze them locally. This option is available under the โAdvanced detailsโ section of the process window.
๐๐๐ฅ๐ฐ๐๐ซ๐ ๐๐จ๐ง๐๐ข๐ ๐๐ฑ๐ญ๐ซ๐๐๐ญ๐จ๐ซ๐ฌ
ANY.RUN has added 4 new extractors to the sandbox: PrivateLoader, Typhon, LaplasClipper and LummaStealer. Also, ANY.RUN has completely updated AgentTesla's config extractors.
๐๐๐๐ ๐ซ๐ฎ๐ฅ๐๐ฌ
ANY.RUN released YARA rules that detect ๐ ๐ก๐๐ฌ๐ญ๐๐ข๐ง๐ฌ and ๐ณ๐ ๐ซ๐๐ญ.
๐๐๐ฐ ๐๐๐ฅ๐ฐ๐๐ซ๐ ๐๐ง๐ ๐๐ก๐ซ๐๐๐ญ ๐๐๐ญ๐๐๐ญ๐ข๐จ๐ง ๐๐ฎ๐ฅ๐๐ฌ
โข 367 new detection rules added.
โข QuasarRAT connection detection.
โข Added 9 rules to detect suspicious PowerShell scripts.
โข Gh0stCringe tool detection.
โข Exfiltration to Discord and Telegram.
๐๐ง๐๐ซ๐๐๐ฌ๐๐ ๐ญ๐ก๐ซ๐๐๐ญ ๐๐จ๐ฏ๐๐ซ๐๐ ๐
โข Bibleoteka backdoor discovery.
โข PseudoManuscrypt access.
โข Malware on file-sharing services.
โข Faster Xworm detection.
โข Response to Medusa Stealer.
๐๐๐.๐๐๐ โโ๐๐จ๐จ๐ฉ๐๐ซ๐๐ญ๐ข๐จ๐ง ๐ฐ๐ข๐ญ๐ก ๐๐ ๐๐๐๐ฌ
Now ANY.RUN shares their rules with the community, ObserverStealer, Medusa Stealer, RisePro TCP v.0.1, Lumma Stealer Configuration, StatusRecorder, and DynamicRAT signatures have been added.
The ANY.RUN team works hard to keep up with emerging threats.
Read more with examples in the article at ANY.RUN.
Vlada Belousova
ANYRUN FZCO
2027889264
email us here
Visit us on social media:
Twitter
YouTube
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.
