Skip to main content
← Back to Demos
Malware advanced · 15 min

Sandbox flags screen-capture followed by data exfiltration

Screen capture is a staple of information-stealing malware: implants periodically snapshot the display to harvest credentials, financial dashboards, and one-time codes before they are used. In this demo, a benign executable performs a single screen capture followed by a simulated outbound transfer to illustrate the pattern. Adaptive Sandbox detonates the executable in an isolated Windows environment and correlates the screen-capture API calls with subsequent network activity, flagging the capture-then-exfiltrate sequence as suspicious. The payload is a benign screenshot test that touches no real data, so the demo is safe to run end to end.

Attack Technique

Screen capture + exfiltration

MITRE ATT&CK

T1113 ↗

Platforms

linuxmacoswindows

File Types

.sh

MetaDefender Capabilities

Adaptive Sandbox
--- ---