Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.3.3. File Analysis and Sandboxing

💡 First Principle: Static file analysis identifies what a file looks like; dynamic analysis (sandboxing) reveals what it does — and malware designed to evade static detection may still reveal itself through its behavior during execution.

Static file analysis examines a file without executing it:

  • Hashing (MD5, SHA-256) creates a unique fingerprint. Comparing against known-malware databases (VirusTotal, NSRL) quickly identifies known threats. New/unknown hashes don't mean safe — just not previously seen.
  • String extraction (strings command) finds human-readable text embedded in binaries: URLs, IP addresses, error messages, function names. A binary containing http://185.220.101.x/download and CreateRemoteThread is suspicious even before execution.
  • VirusTotal submits file hashes or files to 70+ antivirus engines simultaneously. Note: submitting actual files shares them with VirusTotal's database — appropriate for unknown malware but check policies before submitting proprietary files.

Dynamic analysis (sandboxing) executes the suspicious file in an isolated environment and observes its behavior: what files it creates, what processes it spawns, what network connections it makes, what registry changes it makes.

Sandbox ToolCharacteristics
Cuckoo SandboxOpen source, self-hosted, highly customizable
Joe SandboxCommercial, cloud-based, deep analysis reports
Any.runInteractive cloud sandbox — analyst can interact during execution
VirusTotalBehavioral-analysis reports via integrated third-party sandboxes (limited free tier)

Sandboxing limitations: sophisticated malware detects sandbox environments (VM detection, delayed execution, checking for user activity) and doesn't execute its payload when sandboxed. This is a known limitation — a "clean" sandbox run doesn't definitively prove the file is safe.

DNS and IP Reputation Tools:
  • WHOIS — Reveals domain registration information (registrar, registration date, registrant). A domain registered yesterday with privacy-protected WHOIS that's receiving C2 traffic is highly suspicious.
  • AbuseIPDB — Community database of IP addresses reported for malicious activity (spam, scanning, C2). Check destination IPs when investigating suspicious outbound connections.

⚠️ Exam Trap: A file that returns "not detected" from VirusTotal is not confirmed safe — it may be a new variant, a targeted attack tool not in the database, or a file that's been slightly modified to change its hash. Hash evasion (changing one byte) defeats hash-based detection while leaving functionality intact.

Reflection Question: A sandbox analysis of a suspicious email attachment shows no network connections, no file writes, and no process spawns. A junior analyst marks it as benign. What technique might explain these results, and what additional analysis steps would you take?

Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications