Skip to main content
← Back to Demos
Malware intermediate · 15 min

Sandbox replays multi-stage dropper execution chain

The Gentlemen ransomware group, which has claimed 478 victims, spreads worm-like across networks through self-propagating delivery — exactly the kind of multi-stage attack chain defenders must analyze before patient zero is reached. In a multi-stage dropper, a small first-stage binary fetches and executes additional payloads from remote infrastructure, an ingress technique mapped to T1105 that hides the final malware until runtime. This demo runs a benign two-stage dropper whose second stage simply launches Calculator, letting teams safely observe the execution chain. Adaptive Sandbox replays the full behavior — file drops, process creation, and network calls — in an isolated environment and reports an executive-ready verdict.

Attack Technique

Multi-stage dropper

MITRE ATT&CK

T1105 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---