CAPE Sandbox
822 posts

CAPE Sandbox
@CapeSandbox
Payloads or it didn't happen. https://t.co/rAVsWT6dcl
Katılım Nisan 2017
114 Takip Edilen4.7K Takipçiler

I want to share something. I don't expect anyone to care. I just want to scream into the void.
I've accomplished everything I've ever wanted to do with malware. There isn't really a malware thingy that's popped up that I haven't seen or done. My malware code repository of stuff I've written dates back to like, 2009. I've released dozens upon dozens of never before seen (at least publicly) malware snippets and ideas.
I'm standing at this weird cross road where I'm standing at the peak and I'm kind of looking around like ???. What do I do now?
Options:
1. Keep finding new stuff for usermode Windows malware
2. Venture outside usermode to kernel mode malware
3. Switch focus, focus on initial access or stager stuff, not final payload
4. Switch focus, focus outside Windows to different platforms
5. Switch to defense, develop ways to detect malware
6. ???
There is always more to learn and do. But, I've been climbing vertically for like, 20 years, and in order to keep climbing I need to find a different path.
English

Hi @CapeSandbox, can you please activate my account saransh@synthlane
English

@CapeSandbox Could you activate my account (user: nalves599)? Thanks
English

Hey @CapeSandbox, would it be possible to get my account activated? Same username as here - rhysperry111.
Currently analysing some malware that takes almost 18 minutes to run its payload, and there's no chance I can do that with any.run :p
English

@bartblaze @CapeSandbox @D00m3dR4v3n @CapeSandbox
Hello! Can you activate my account? Username: fundakaraoglu
English
CAPE Sandbox retweetledi

Malware abusing the finger protocol (this one makes a comeback now and again).
bleepingcomputer.com/news/security/…
Caught with @CapeSandbox :)

English

#Amatera payload extraction & direct syscall capture
capesandbox.com/analysis/11082/



Jai Minton@CyberRaiju
New Octowave Loader sample > Amatera Stealer. 0 VT. Proofpoint rules detect the traffic. My Yara rule detects the installer. Adobe printer driver sideloads tbb.dll, tbb.dll loads app-2.3.dll which gets stego from blood.wav, uses zxing.presentation.dll. virustotal.com/gui/file/f5c8b…
English

Hello @CapeSandbox ! Would you be so kind as to activate my account? The username is "cy0x"
English

@CapeSandbox Hi @CapeSandbox. Could i get my account activated?
username: Dorian
Much appreciated!
English

New cmd.exe batch deobfuscation capability integrated in CAPE! FindFixAndRun hook😎
For example: capesandbox.com/analysis/23842/
Thanks KingKDot github.com/KingKDot/Exorc…🙏
and KillerInstinct for the integration!

English

@CapeSandbox Hi! I’d like to activate an account on capesandbox.com. My username is ckoolaide. Could you please assist? Thank you!
English

@CapeSandbox Hello @CapeSandbox, could you please activate my account with the username moonsolo? Much appreciated!
English

@CapeSandbox yello, i'd like to request account activation for ninetailedfox
English

@CapeSandbox Hi, is it possible to have my account activated? My username is alessandromarchetti. I did another registration yesterday with the username alessandromarchetti_dr that was tied to the wrong email, it can be deleted. Thank you and sorry for the double sign up.
English

@dnssafixxi Sorry this is not a commercial thing, there is no premium subscription. It's just an open source project with a demo instance!
English

@dnssafixxi Yes it is configurable in web.conf
github.com/kevoreilly/CAP…
English


