← Back to Demos
Malware advanced · 15 min
Sandbox flags screen-capture followed by data exfiltration
Screen capture is a staple of information-stealing malware: implants periodically snapshot the display to harvest credentials, financial dashboards, and one-time codes before they are used. In this demo, a benign executable performs a single screen capture followed by a simulated outbound transfer to illustrate the pattern. Adaptive Sandbox detonates the executable in an isolated Windows environment and correlates the screen-capture API calls with subsequent network activity, flagging the capture-then-exfiltrate sequence as suspicious. The payload is a benign screenshot test that touches no real data, so the demo is safe to run end to end.
Attack Technique
Screen capture + exfiltration
MITRE ATT&CK
T1113 ↗Platforms
linuxmacoswindows
File Types
.sh
MetaDefender Capabilities
Adaptive Sandbox