Palo Alto Networks, Inc.
Rendering an object using muliple versions of an application in a single process for dynamic malware analysis

Last updated:

Abstract:

Techniques for rendering an object using multiple versions of an application in a single process for dynamic malware analysis are disclosed. In some embodiments, a system, process, and/or computer program product for rendering an object using multiple versions of an application in a single process for dynamic malware analysis includes receiving a sample at a cloud security service, in which the sample includes an embedded object; detonating the sample using a browser executed in an instrumented virtual machine environment; and rendering the embedded object using a plurality of versions of an application in a single process during a dynamic malware analysis using the instrumented virtual machine environment.

Status:
Grant
Type:

Utility

Filling date:

30 Jun 2016

Issue date:

19 Nov 2019