Palo Alto Networks, Inc.
RENDERING AN OBJECT USING MULTIPLE VERSIONS OF AN APPLICATION IN A SINGLE PROCESS FOR DYNAMIC MALWARE ANALYSIS

Last updated:

Abstract:

Techniques for rendering an object using multiple versions of an application in a single process for dynamic malware analysis are disclosed. In some embodiments, a system, process, and/or computer program product for rendering an object using multiple versions of an application in a single process for dynamic malware analysis includes receiving a sample at a cloud security service, in which the sample includes an embedded object; detonating the sample using a browser executed in an instrumented virtual machine environment; and rendering the embedded object using a plurality of versions of an application in a single process during a dynamic malware analysis using the instrumented virtual machine environment.

Status:
Application
Type:

Utility

Filling date:

17 Sep 2019

Issue date:

9 Jan 2020