building-automated-malware-submission-pipeline - Automate Malware Submission and Sandbox Analysis
Collects suspicious files, checks known hashes, submits unknown samples for sandbox analysis, and produces verdicts and indicators of compromise.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Collect suspicious files
- Compute file hashes
- Check VirusTotal hashes
- Check MalwareBazaar hashes
- Pre-screen malware samples
- Submit files to Cuckoo
- Wait for analysis results
- Extract sandbox indicators
Inputs
- Quarantined endpoint files
- Email gateway attachments
- Network captures
- VirusTotal API key
- MalwareBazaar API access
- Sandbox API endpoint
- Sandbox submission settings
Outputs
- Collected malware samples
- Hash lookup results
- Pre-screen verdicts
- Sandbox task identifiers
- Sandbox analysis reports
- Network indicators
- Dropped-file indicators
- Process and registry indicators
Requirements
- Python 3.8 or later
- requests library
- vt-py library
- pefile library
- Sandbox environment
- VirusTotal API access
- MalwareBazaar API access
- Isolated analysis network
