{"id":53297,"date":"2019-11-28T00:00:00","date_gmt":"2019-11-27T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network"},"modified":"2020-02-18T14:01:11","modified_gmt":"2020-02-18T11:01:11","slug":"1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network","title":{"rendered":"1. Malware analysis using Check Point forensics. SandBlast Network","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/6cdc050d06c58f4213e13826d2a15c65.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWelcome to a new series of articles, this time focusing on incident investigations, specifically analyzing malware using Check Point forensics. Previously, we published <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/358508\/\">a few video tutorials<\/a><\/noindex> on how to use Smart Event, but this time we will examine forensic reports on specific events across various Check Point products:<\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/katalog\/checkpoint\/sandblast\">SandBlast Network<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/reshenie\/sandblast-agent\">SandBlast Agent<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/reshenie\/mobile-threat-defense\">SandBlast Mobile<\/a><\/noindex><\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/www.checkpoint.com\/ru\/products\/cloud-security\/\">CloudGuard SaaS<\/a><\/noindex><\/li>\n<\/ul>\n<p>\nWhy is forensics of prevented incidents important? It may seem that catching a virus is already good, but why delve deeper into it? As experience shows, it's preferable not just to block an attack but to understand how it works: what the entry point was, what vulnerability was exploited, what processes were involved, whether the registry and file system were affected, the virus family, potential damage, etc. Such valuable information can be obtained from comprehensive forensic reports by Check Point (both textual and graphical). Manually generating such a report is very challenging. This data can then aid in taking necessary measures and preventing similar attacks in the future. Today, we will review the Check Point SandBlast Network forensic report.<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>SandBlast Network<\/h3>\n<p>\nThe use of sandboxes to enhance network perimeter protection has long become standard practice and an essential component, just like IPS. Check Point's Threat Emulation blade is responsible for sandbox functionality, which is part of the SandBlast technologies (there's also Threat Extraction). We previously published <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/325822\/\">a brief course on Check Point SandBlast<\/a><\/noindex> for the Gaia 77.30 version (highly recommend watching if you don't understand what we are discussing now). Architecturally, nothing fundamentally has changed since then. If you have a Check Point Gateway at your network perimeter, you can use two integration options with the sandbox:<\/p>\n<ol>\n<li><b>SandBlast Local Appliance<\/b> \u2014 an additional SandBlast appliance is installed in your network, to which files are sent for analysis.<\/li>\n<li><b>SandBlast Cloud<\/b> \u2014 files are sent to Check Point's cloud for analysis.<\/li>\n<\/ol>\n<p>\n<img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/6c95d4e982dae312491c23a74c2fc8c1.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nA sandbox can be considered the last line of defense on the network perimeter. It connects only after traditional analysis using antivirus and IPS. While these conventional signature-based tools provide little analytical insight, the sandbox can thoroughly explain why a file was blocked and what malicious actions it was taking. Such a forensics report can be obtained from both local and cloud-based sandboxes.<\/p>\n<h3>Check Point Forensics Report<\/h3>\n<p>\nImagine you, as an information security specialist, arrive at work and open the dashboard in SmartConsole. Right away, you see incidents from the last 24 hours, and your attention is drawn to Threat Emulation events \u2014 the most dangerous attacks that were not blocked by signature analysis.<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/0510430e48fe0a2a766d52fec720c47b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nYou can 'drill down' into these events and review all logs related to the Threat Emulation blade.<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/e0f2eef5df971696c2b8fbc521f82094.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAfter this, you can further filter the logs by threat severity level and Confidence Level:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/27e224aeebdd34a8e1ee00b9da492180.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nBy revealing the event of interest, you can review general information (src, dst, severity, sender, etc.):<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/a7add16c7ce9fe7336d469574e339964.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAnd there you can also see the section <b>Forensics<\/b> with an available <b>Summary<\/b> report. By clicking on it, a detailed analysis of the malware will open in the form of an interactive HTML page:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/1b5619fc6824b3695aacbbeaa277e622.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n(This is part of the page. <noindex><a rel=\"nofollow\" href=\"https:\/\/eolkov.github.io\/checkpoint-forensics\/\">The original can be viewed here<\/a><\/noindex>)<\/p>\n<p>From this report, we can download the original malware (in a password-protected archive), or directly contact the Check Point response team.<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/8769a6424bda34fd37117227d8d91933.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nA little lower, you can see a nice animation that shows, in percentage terms, how our instance correlates with known malicious code (including the code itself and macros). This analysis is provided using machine learning in the Check Point Threat Cloud.<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/93cdd13ab6ff751cbd04dcf0c5a4eec9.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNext, you can see which specific sandbox activities led to the conclusion of the file's maliciousness. In this case, we see the use of evasion techniques and an attempt to load ransomware:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/1f09eec9a452bbc3bdb5d79321984767.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nYou may notice that in this case, the emulation was performed in two systems (Win 7, Win XP) and different software versions (Office, Adobe). Below is a video (slideshow) of the process of opening this file in the sandbox:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/1691a0182ae9e24f299b285ddd189614.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nSample video:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/4592c38017531a8a376c065c9a88ad3e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAt the very end, we can see in detail how the attack progressed, either in tabular form or graphically:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/34ead6a4a18cf9e0fee9ef61d30aa4c3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThere, we can download this information in RAW format and a pcap file for detailed analysis of the generated traffic in Wireshark:<\/p>\n<p><img decoding=\"async\" alt=\"1. Malware analysis using Check Point forensics. SandBlast Network\" src=\"\/wp-content\/uploads\/2019\/11\/9fdfca16b80a62288adda4f51f013be3.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>Conclusion<\/h3>\n<p>\nUsing this information, you can significantly enhance your network's security. You can block hosts that distribute viruses, close active vulnerabilities, prevent potential feedback to C&amp;C, and much more. Don't neglect this analysis.<\/p>\n<p>In the upcoming articles, we will similarly review reports from SandBlast Agent, SandBlast Mobile, as well as CloudGuard SaaS. So stay tuned for updates (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\">Telegram<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/groups\/tssolution.info\/\">Facebook<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\">VK<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\">TS Solution Blog<\/a><\/noindex>)!<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/477494\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 \u043d\u043e\u0432\u044b\u0439 \u0446\u0438\u043a\u043b \u0441\u0442\u0430\u0442\u0435\u0439, \u043d\u0430 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u043f\u043e \u0442\u0435\u043c\u0435 \u0440\u0430\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0438\u043d\u0446\u0438\u0434\u0435\u043d\u0442\u043e\u0432, \u0430 \u0438\u043c\u0435\u043d\u043d\u043e \u2014 \u0430\u043d\u0430\u043b\u0438\u0437\u0443 \u0437\u043b\u043e\u0432\u0440\u0435\u0434\u043e\u0432 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0444\u043e\u0440\u0435\u043d\u0437\u0438\u043a\u0438 Check Point. \u0420\u0430\u043d\u0435\u0435 \u043c\u044b \u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0432\u0438\u0434\u0435\u043e \u0443\u0440\u043e\u043a\u043e\u0432 \u043f\u043e \u0440\u0430\u0431\u043e\u0442\u0435 \u0432 Smart Event, \u043d\u043e \u043d\u0430 \u044d\u0442\u043e\u0442 \u0440\u0430\u0437 \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u043e\u0442\u0447\u0435\u0442\u044b \u0444\u043e\u0440\u0435\u043d\u0437\u0438\u043a\u0438 \u043f\u043e \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u044b\u043c \u0441\u043e\u0431\u044b\u0442\u0438\u044f\u043c \u0432 \u0440\u0430\u0437\u043d\u044b\u0445 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u0430\u0445 Check Point: SandBlast Network SandBlast Agent SandBlast [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-53297","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd471. \u0410\u043d\u0430\u043b\u0438\u0437 \u0437\u043b\u043e\u0432\u0440\u0435\u0434\u043e\u0432 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0444\u043e\u0440\u0435\u043d\u0437\u0438\u043a\u0438 Check Point. SandBlast Network | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-27T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd471. Malware analysis using Check Point forensics. SandBlast Network | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd471. \u0410\u043d\u0430\u043b\u0438\u0437 \u0437\u043b\u043e\u0432\u0440\u0435\u0434\u043e\u0432 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0444\u043e\u0440\u0435\u043d\u0437\u0438\u043a\u0438 Check Point. SandBlast Network | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/1-analiz-zlovredov-s-pomoshhyu-forenziki-check-point-sandblast-network","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-27T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53297","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 06:50:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:27:39","updated":"2026-01-24 06:50:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/53297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=53297"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/53297\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=53297"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=53297"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=53297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}