Dynamic Analysis
The Spectra Analyze appliance optionally integrates with several dynamic analysis services, making it possible to automatically send samples for dynamic analysis, as well as to reanalyze samples using any of the supported services.
The ReversingLabs Cloud Sandbox can, optionally, be configured to affect the final sample classification. Third-party dynamic analysis results do not affect the overall final classification of the sample, but are, rather, another source of information for analysts.
Dynamic analysis services must be configured on the Administration > Integrations page by the appliance administrator. On that page, EDIT which file types you would like to analyze with each configured integration.
The integrations work with samples submitted through the graphical user interface (with the Submit file, Submit URL, and Reanalyze options), as well as with those submitted via the Submissions API. Dynamic analysis results are displayed on the Sample Details page of each analyzed sample.
Some integrations have the option to submit only distinct files. When this option is enabled, if a file has already been submitted to Spectra Analyze and analyzed, it will not be sent for reanalysis when it is submitted again. This option applies to files submitted to Spectra Analyze using the graphical user interface and via the Upload API. It does not affect the Reanalysis feature - you can still submit files for reanalysis with any of the integrations even if the files have already been analyzed. By default, this option is disabled for every integration.
ReversingLabs Cloud Sandbox
Spectra Analyze is integrated with the ReversingLabs dynamic analysis API, providing historical information on all dynamic analyses performed on the detonated sample, with detected indicators of compromise available through Advanced Search (using the uri-dynamic
and ipv4-dynamic
keywords), as well as through sections on the Sample Summary page.
For this service to be available, the appliance has to be connected to Spectra Intelligence. If the service is enabled, historic dynamic analysis results are shown for all samples that have them.
Dynamic Analysis Reports
Full report details consist of:
- General file details
- A thumbnail of one of the screenshots generated during analysis. Clicking the screenshot opens a gallery of all collected screenshots, with the option to automatically advance through them in a slideshow. At the top of the gallery dialog, users can switch between different analyses to see the related screenshots.
- Analysis history with the option to download dropped files and other artifacts for every individual analysis. These files are available for download for 1 year.
- Tabbed section with specific information obtained in dynamic analysis. This section can be filtered to show information from all performed analyses, or from a specific analysis.
MITRE ATT&CK
Techniques detected during dynamic analysis. This table shows techniques detected during file execution, and will differ from the MITRE ATT&CK table produced by Spectra Core static analysis.
Malware Configurations
C2 server URLs and IP addresses.
Network
Network resources contacted by the sample during execution.
Behavioral
List of processes the sample spawned and the actions they performed.