Sandbox replays multi-stage dropper execution chain
The Gentlemen ransomware group, which has claimed 478 victims, spreads worm-like across networks through self-propagating delivery — exactly the kind of multi-stage attack chain defenders must analyze before patient zero is reached. In a multi-stage dropper, a small first-stage binary fetches and executes additional payloads from remote infrastructure, an ingress technique mapped to T1105 that hides the final malware until runtime. This demo runs a benign two-stage dropper whose second stage simply launches Calculator, letting teams safely observe the execution chain. Adaptive Sandbox replays the full behavior — file drops, process creation, and network calls — in an isolated environment and reports an executive-ready verdict.
Attack Technique
Multi-stage dropper
MITRE ATT&CK
T1105 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗