Loading...

Upload & Start Analysis

Upload a file and automatically start malware analysis with VM provisioning.

File *

Your malware file to execute on the VM

Submission Profile *

The VM / EDR you want to test against

Submission Execution Mode *

AutoIt is more realistic for initial access payloads. Will "click" the file (and container).
Direct execution invokes the target directly. Supports .exe arguments. Supports .dll. For testing tools. Clickfix will interpret the content of the file as single line string to be inserted into the run dialog.

Submission Runtime (seconds)

How long the payload runs. Increase this to observe post-ex behaviors like beacon callbacks.

Accepted range: 3 - 7200 seconds. Default 10 seconds.

Submission Malware Execution Path

The target directory path where the malware should be initially placed on the virtual machine

Default: C:\Users\Public\Downloads\
Whitelisted execution: C:\RedEdr\data\

File Source URL

[Optional] URL pointing to more information about the payload

File Comment

[Optional] description of the payload. What loader, C2 payload etc.

Submission Comment

[Optional] description of what you're testing or trying to achieve with this analysis. Include your hypothesis, what detection capabilities you're evaluating, or research objectives

Submission Project

[Optional] project name to group related submissions together