Explanation

The chart is a summary of the analysis of binaries through our sandboxing system. The different fields in the report are as follows:

Programs Processed - How many binaries went through the system

  1. Programs Skipped - Using different hashing methodologies we are able to identify common polymorphistic files and skip the processing
  2. Programs Analyzed - How many binaries actually were submitted to the Sandbox system and analyized
    • Completed Analysis Runs - How many of the submitted binaries completed successfully and had some sort of results
    • Failed Analysis Runs - Binaries that would not run and create a valid report
    • Programs Retried - How many binaries were re-run. All binaries that initially fail will be re-run for more attempts to properly execute and gain an analysis of that program
    • Invalid Binaries - How many program that would not execute or were not proper Windows binaries
  3. Network Traffic Statistics - Of the programs that were processed and had output, which had network based traffic and the breakdown of the different types of network traffic seen for the binaries
  4. Anti-Analysis Techniques - Many of the different malware programs will take defensive measures to prevent analysis and reverse engineering. These are the different forms and results that we are able to determine from the successfully tested programs
  5. Malicious Activity - What activity local to the system will the programs take

↑ Contents

Updates

The chart is updated once every four hours and is for the last rolling ten days and 30 days of statistics.

↑ Contents

Sandbox Processing

FTP Results

HTTP Results

IRC Results

P2P Results

SMTP Results

↑ Contents

Sandbox Statistics (10-Day Rolling Report)

---------------------------------------------  ----------  ----------
Sandbox Results                                    Totals     Percent
---------------------------------------------  ----------  ----------
Programs Processed                              5,158,464            
  Programs Skipped                              4,499,060       87.2%
  Programs Analyzed                               659,404       12.8%
    Completed Analysis Runs                       658,616       99.9%
    Failed Analysis Runs                                0        0.0%
    Programs Retried                                    0        0.0%
    Invalid Binaries                                  788        0.1%
                                                                     
---------------------------------------------  ----------  ----------
Network Traffic Statistics                         Totals     Percent
---------------------------------------------  ----------  ----------
Programs that sent TCP data                       530,656       80.6%
  Programs using HTTP                             223,002       42.0%
    URLs captured                                       0            
  Programs using FTP                                1,879        0.4%
  Programs using SMTP                                 208        0.0%
  Programs using IRC                                4,235        0.8%
Programs that sent UDP data                       604,402       91.8%
  Programs that made DNS requests                 604,402      100.0%
Programs that made P2P connections                     11        0.0%
    Programs using bittorrent                           9       81.8%
    Programs using edonkey                              0        0.0%
    Programs using gnutella                             1        9.1%
    Programs using winmx                                1        9.1%
                                                                     
---------------------------------------------  ----------  ----------
Anti-Analysis Techniques                           Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made debugger checks                      0        0.0%
Programs that made VMWare registry checks               0        0.0%
Programs that made SoftICE checks                       0        0.0%
Programs that made Wine checks                          0        0.0%
Programs that made Time checks                          0        0.0%
Programs that supress Compatibility Warnings            0        0.0%
                                                                     
---------------------------------------------  ----------  ----------
Malicious Activity                                 Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made Windows Firewall Updates             0        0.0%
Programs that installed a Rootkit                       0        0.0%
Programs that installed a startup entry                 0        0.0%
Programs that accessed user's Firefox profile           0        0.0%
Programs that accessed the Pstore                       0        0.0%
Programs that called taskkill                           0        0.0%

↑ Contents

Sandbox Statistics (30-Day Rolling Report)

---------------------------------------------  ----------  ----------
Sandbox Results                                    Totals     Percent
---------------------------------------------  ----------  ----------
Programs Processed                             16,755,415            
  Programs Skipped                             15,001,169       89.5%
  Programs Analyzed                             1,754,246       10.5%
    Completed Analysis Runs                     1,751,593       99.8%
    Failed Analysis Runs                                0        0.0%
    Programs Retried                                    0        0.0%
    Invalid Binaries                                2,653        0.2%
                                                                     
---------------------------------------------  ----------  ----------
Network Traffic Statistics                         Totals     Percent
---------------------------------------------  ----------  ----------
Programs that sent TCP data                     1,530,255       87.4%
  Programs using HTTP                             765,772       50.0%
    URLs captured                                       0            
  Programs using FTP                                4,503        0.3%
  Programs using SMTP                               1,645        0.1%
  Programs using IRC                               13,904        0.9%
Programs that sent UDP data                     1,707,445       97.5%
  Programs that made DNS requests               1,707,417      100.0%
Programs that made P2P connections                     36        0.0%
    Programs using bittorrent                          28       77.8%
    Programs using edonkey                              2        5.6%
    Programs using gnutella                             4       11.1%
    Programs using winmx                                2        5.6%
                                                                     
---------------------------------------------  ----------  ----------
Anti-Analysis Techniques                           Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made debugger checks                      0        0.0%
Programs that made VMWare registry checks               0        0.0%
Programs that made SoftICE checks                       0        0.0%
Programs that made Wine checks                          0        0.0%
Programs that made Time checks                          0        0.0%
Programs that supress Compatibility Warnings            0        0.0%
                                                                     
---------------------------------------------  ----------  ----------
Malicious Activity                                 Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made Windows Firewall Updates             0        0.0%
Programs that installed a Rootkit                       0        0.0%
Programs that installed a startup entry                 0        0.0%
Programs that accessed user's Firefox profile           0        0.0%
Programs that accessed the Pstore                       0        0.0%
Programs that called taskkill                           0        0.0%

↑ Contents

Sandbox Statistics (60-Day Rolling Report)

---------------------------------------------  ----------  ----------
Sandbox Results                                    Totals     Percent
---------------------------------------------  ----------  ----------
Programs Processed                             31,378,412            
  Programs Skipped                             27,940,807       89.0%
  Programs Analyzed                             3,437,605       11.0%
    Completed Analysis Runs                     3,432,372       99.8%
    Failed Analysis Runs                                0        0.0%
    Programs Retried                                    0        0.0%
    Invalid Binaries                                5,233        0.2%
                                                                     
---------------------------------------------  ----------  ----------
Network Traffic Statistics                         Totals     Percent
---------------------------------------------  ----------  ----------
Programs that sent TCP data                     2,902,813       84.6%
  Programs using HTTP                           1,543,894       53.2%
    URLs captured                                       0            
  Programs using FTP                                4,795        0.2%
  Programs using SMTP                               5,956        0.2%
  Programs using IRC                               18,076        0.6%
Programs that sent UDP data                     3,306,443       96.3%
  Programs that made DNS requests               3,306,439      100.0%
Programs that made P2P connections                     69        0.0%
    Programs using bittorrent                          58       84.1%
    Programs using edonkey                              3        4.3%
    Programs using gnutella                             5        7.2%
    Programs using winmx                                3        4.3%
                                                                     
---------------------------------------------  ----------  ----------
Anti-Analysis Techniques                           Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made debugger checks                      0        0.0%
Programs that made VMWare registry checks               0        0.0%
Programs that made SoftICE checks                       0        0.0%
Programs that made Wine checks                          0        0.0%
Programs that made Time checks                          0        0.0%
Programs that supress Compatibility Warnings            0        0.0%
                                                                     
---------------------------------------------  ----------  ----------
Malicious Activity                                 Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made Windows Firewall Updates             0        0.0%
Programs that installed a Rootkit                       0        0.0%
Programs that installed a startup entry                 0        0.0%
Programs that accessed user's Firefox profile           0        0.0%
Programs that accessed the Pstore                       0        0.0%
Programs that called taskkill                           0        0.0%

↑ Contents

Sandbox Statistics (90-Day Rolling Report)

---------------------------------------------  ----------  ----------
Sandbox Results                                    Totals     Percent
---------------------------------------------  ----------  ----------
Programs Processed                             49,580,794            
  Programs Skipped                             44,978,819       90.7%
  Programs Analyzed                             4,601,975        9.3%
    Completed Analysis Runs                     4,595,799       99.9%
    Failed Analysis Runs                                0        0.0%
    Programs Retried                                    0        0.0%
    Invalid Binaries                                6,176        0.1%
                                                                     
---------------------------------------------  ----------  ----------
Network Traffic Statistics                         Totals     Percent
---------------------------------------------  ----------  ----------
Programs that sent TCP data                     4,508,649       98.1%
  Programs using HTTP                           2,630,338       58.3%
    URLs captured                                       0            
  Programs using FTP                                5,198        0.1%
  Programs using SMTP                               7,401        0.2%
  Programs using IRC                               25,066        0.6%
Programs that sent UDP data                     4,485,499       97.6%
  Programs that made DNS requests               4,485,499      100.0%
Programs that made P2P connections                     84        0.0%
    Programs using bittorrent                          67       79.8%
    Programs using edonkey                              5        6.0%
    Programs using gnutella                             9       10.7%
    Programs using winmx                                3        3.6%
                                                                     
---------------------------------------------  ----------  ----------
Anti-Analysis Techniques                           Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made debugger checks                      0        0.0%
Programs that made VMWare registry checks               0        0.0%
Programs that made SoftICE checks                       0        0.0%
Programs that made Wine checks                          0        0.0%
Programs that made Time checks                          0        0.0%
Programs that supress Compatibility Warnings            0        0.0%
                                                                     
---------------------------------------------  ----------  ----------
Malicious Activity                                 Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made Windows Firewall Updates             0        0.0%
Programs that installed a Rootkit                       0        0.0%
Programs that installed a startup entry                 0        0.0%
Programs that accessed user's Firefox profile           0        0.0%
Programs that accessed the Pstore                       0        0.0%
Programs that called taskkill                           0        0.0%

↑ Contents

Sandbox Statistics (180-Day Rolling Report)

---------------------------------------------  ----------  ----------
Sandbox Results                                    Totals     Percent
---------------------------------------------  ----------  ----------
Programs Processed                             78,670,023            
  Programs Skipped                             70,652,772       89.8%
  Programs Analyzed                             8,017,251       10.2%
    Completed Analysis Runs                     7,969,026       99.4%
    Failed Analysis Runs                            2,453        0.0%
    Programs Retried                               24,035        0.3%
    Invalid Binaries                               21,737        0.3%
                                                                     
---------------------------------------------  ----------  ----------
Network Traffic Statistics                         Totals     Percent
---------------------------------------------  ----------  ----------
Programs that sent TCP data                     7,181,293       90.1%
  Programs using HTTP                           4,052,261       56.4%
    URLs captured                              11,303,920            
  Programs using FTP                               28,590        0.4%
  Programs using SMTP                              16,451        0.2%
  Programs using IRC                               36,924        0.5%
Programs that sent UDP data                     7,777,769       97.6%
  Programs that made DNS requests               7,777,769      100.0%
Programs that made P2P connections                    196        0.0%
    Programs using bittorrent                         165       84.2%
    Programs using edonkey                              9        4.6%
    Programs using gnutella                            17        8.7%
    Programs using winmx                                5        2.6%
                                                                     
---------------------------------------------  ----------  ----------
Anti-Analysis Techniques                           Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made debugger checks                      0        0.0%
Programs that made VMWare registry checks               0        0.0%
Programs that made SoftICE checks                       0        0.0%
Programs that made Wine checks                          0        0.0%
Programs that made Time checks                          0        0.0%
Programs that supress Compatibility Warnings            0        0.0%
                                                                     
---------------------------------------------  ----------  ----------
Malicious Activity                                 Totals     Percent
---------------------------------------------  ----------  ----------
Programs that made Windows Firewall Updates             0        0.0%
Programs that installed a Rootkit                       0        0.0%
Programs that installed a startup entry                 0        0.0%
Programs that accessed user's Firefox profile           0        0.0%
Programs that accessed the Pstore                       0        0.0%
Programs that called taskkill                           0        0.0%

↑ Contents

Sandbox Statistics (One-Year Rolling Report)

---------------------------------------------   ----------  ----------
Sandbox Results                                     Totals     Percent
---------------------------------------------   ----------  ----------
Programs Processed                             132,714,933            
  Programs Skipped                             118,019,655       88.9%
  Programs Analyzed                             14,695,278       11.1%
    Completed Analysis Runs                     14,492,889       98.6%
    Failed Analysis Runs                            13,460        0.1%
    Programs Retried                               158,293        1.1%
    Invalid Binaries                                30,636        0.2%
                                                                      
---------------------------------------------   ----------  ----------
Network Traffic Statistics                          Totals     Percent
---------------------------------------------   ----------  ----------
Programs that sent TCP data                     10,477,898       72.3%
  Programs using HTTP                            5,848,562       55.8%
    URLs captured                               31,414,549            
  Programs using FTP                                62,750        0.6%
  Programs using SMTP                               33,737        0.3%
  Programs using IRC                                47,809        0.5%
Programs that sent UDP data                     14,145,059       97.6%
  Programs that made DNS requests               14,145,059      100.0%
Programs that made P2P connections                     687        0.0%
    Programs using bittorrent                          520       75.7%
    Programs using edonkey                              20        2.9%
    Programs using gnutella                             97       14.1%
    Programs using winmx                                50        7.3%
                                                                      
---------------------------------------------   ----------  ----------
Anti-Analysis Techniques                            Totals     Percent
---------------------------------------------   ----------  ----------
Programs that made debugger checks                       0        0.0%
Programs that made VMWare registry checks                0        0.0%
Programs that made SoftICE checks                        0        0.0%
Programs that made Wine checks                           0        0.0%
Programs that made Time checks                           0        0.0%
Programs that supress Compatibility Warnings             0        0.0%
                                                                      
---------------------------------------------   ----------  ----------
Malicious Activity                                  Totals     Percent
---------------------------------------------   ----------  ----------
Programs that made Windows Firewall Updates              0        0.0%
Programs that installed a Rootkit                        0        0.0%
Programs that installed a startup entry                  0        0.0%
Programs that accessed user's Firefox profile            0        0.0%
Programs that accessed the Pstore                        0        0.0%
Programs that called taskkill                            0        0.0%

Sandbox Statistics (Two-Year Rolling Report)

---------------------------------------------   ----------  ----------
Sandbox Results                                     Totals     Percent
---------------------------------------------   ----------  ----------
Programs Processed                             205,381,708            
  Programs Skipped                             176,062,542       85.7%
  Programs Analyzed                             29,319,166       14.3%
    Completed Analysis Runs                     27,951,753       95.3%
    Failed Analysis Runs                           289,199        1.0%
    Programs Retried                             1,046,449        3.6%
    Invalid Binaries                                31,765        0.1%
                                                                      
---------------------------------------------   ----------  ----------
Network Traffic Statistics                          Totals     Percent
---------------------------------------------   ----------  ----------
Programs that sent TCP data                     14,857,346       53.2%
  Programs using HTTP                            8,707,715       58.6%
    URLs captured                               57,914,357            
  Programs using FTP                                99,226        0.7%
  Programs using SMTP                               58,062        0.4%
  Programs using IRC                                79,704        0.5%
Programs that sent UDP data                     27,280,910       97.6%
  Programs that made DNS requests               27,280,910      100.0%
Programs that made P2P connections                   1,684        0.0%
    Programs using bittorrent                        1,322       78.5%
    Programs using edonkey                              77        4.6%
    Programs using gnutella                            210       12.5%
    Programs using winmx                                75        4.5%
                                                                      
---------------------------------------------   ----------  ----------
Anti-Analysis Techniques                            Totals     Percent
---------------------------------------------   ----------  ----------
Programs that made debugger checks                 867,605        3.1%
Programs that made VMWare registry checks            4,186        0.0%
Programs that made SoftICE checks                   23,027        0.1%
Programs that made Wine checks                      25,358        0.1%
Programs that made Time checks                         883        0.0%
Programs that supress Compatibility Warnings     3,008,837       10.8%
                                                                      
---------------------------------------------   ----------  ----------
Malicious Activity                                  Totals     Percent
---------------------------------------------   ----------  ----------
Programs that made Windows Firewall Updates            463        0.0%
Programs that installed a Rootkit                      200        0.0%
Programs that installed a startup entry            575,159        2.1%
Programs that accessed user's Firefox profile            0        0.0%
Programs that accessed the Pstore                   54,059        0.2%
Programs that called taskkill                            0        0.0%

↑ Contents

<< Malware | Statistics | Sandbox Graphs >>