Sandboxie + Buster Sandbox Analyzer

打造属于你自己的病毒分析实验室

    Sandbox (沙盒)技术:是一种安全机制隔离运行的程序,使用驱动拦截写操作(注册表,磁盘等)

1.Sandboxie 和 Buster Sandbox Analyzer 简介

    (1).Sandboxie

    Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.

 

    (2).Buster Sandbox Analyzer

    Buster Sandbox Analyzer is a tool that has been designed to analyze the behaviour of processes and the changes made to system and then evaluate if they are malware suspicious.

    (3)Sandboxie (或者说其他sandbox)的问题

    现在很多的远程控制软件或者说是一些rootkit等都有Anti-sandbox、anti-debugger功能,看个图

 

所以就有了Buster Sandbox Analyzer

 

    2.安装

    (1).下载Sandboxie         http://www.sandboxie.com/SandboxieInstall.exe

    (2).下载Buster Sandbox Analyzer       http://bsa.isoftware.nl/bsa.rar

    (3).解压bsa.rar到C:\bsa

    (4).运行Sandboxie Control, click Configure at the menu bar, and select Edit Configuration.

    (5).在[DefaultBox]中的最后添加一下内容后保存退出

    InjectDll=C:\bsa\log_api.dll
    OpenWinClass=TFormBSA

    类似

 

    (6).配置 “Sandbox folder to check”

    运行BSA.exe ----运行Sanboxie Control, 右击  Sandbox Defaultbox and select Explore Contents. A window explorer will now open, copy the path and paste it to the “Sandbox folder to check”.

 

    (7).点击 Start Analysis 然后点击 “Delete Sandbox Folder contents and continue“.

    (8).添加你想分析的文件,开始分析

 

注意事项:

1.隐藏Sandboxie 进程 -----参考 http://bsa.isoftware.nl/frameb.htm

2.要分析网络行为必须先安装winpcap

原文:http://www.raymond.cc/blog/archives/2010/07/30/buster-sandbox-analyzer-makes-sandboxie-stronger/

 

Sandboxie 官网:http://sandboxie.com

Buster Sandbox Analyzer 官网:http://bsa.isoftware.nl/

Buster Sandbox Analyzer 支持论坛:www.kernelmode.info/forum/viewtopic.php?f=11&t=139