Every file walks in through the same door.

Mail, shares, upload forms. Malwation meets it in the corridor, before it meets anyone else.

Nothing moves unwatched.

Agent-less sandboxing observes behaviour the way a camera watches a corridor: from outside, and unnoticed by what it is watching.

One desk. Every screen.

Threat.Zone puts syscalls, the MITRE ATT&CK map and the CSI investigation toolkit in front of one analyst.

The wall rebuilds what passes through.

HookMesh routes each file through CDR and the tools you already run, then hands back a clean copy.

Out in the open.

That is the point. Analysis, sanitization and simulation, from one crew.

Contact us

Trusted by

  • Barracuda
  • cirosec
  • Cognyte
  • T.C. Enerji ve Tabii Kaynaklar Bakanlığı
  • Houston Pilots
  • İstanbul Altın Rafinerisi
  • Joon
  • Kariyer.net
  • Leonardo
  • Otosor
  • Pulsec
  • Türk Telekom
  • Trendyol
  • Unimed

One file. Three technologies.

Two products draw on three engines. Threat.Zone runs all three side by side and detonates the file on the system it targets; HookMesh routes each file through static analysis and CDR on rules you set. Both return a verdict and a clean copy of the file.

  • Verdict and reportIndicators, MITRE map, YARA rule. Alerts to your channels.
  • Clean fileThe same document, rebuilt. From either product.
  1. Static analysis

    Every byte is read before anything runs. Structure, packers, signatures and strings, scored in seconds. Both products call it.

    Static Analysis
  2. Sandbox

    Threat.Zone runs the file on Windows, Linux, macOS or Android and watches from outside the machine. Behaviour, MITRE techniques, dropped files, traffic. The same sandbox wherever you run it:

    • On-premise
    • Private tenant
    • Cloud
    Sandbox
  3. CDR

    One engine, called by both products. What is harmful is taken out and the document rebuilt, so a usable copy comes back.

    CDR

What comes back.

A Java loader from a phishing wave against Turkish companies. Every public sandbox and antivirus let it walk; Threat.Zone did not. This is the report it wrote.

Read the full analysis

TEKLIFALINACAKURUNLER.jar

d286acf63f5846e775ba23599e2b5be88d0564d24f29e0646f6cff207249c130

Java archive, three stages. Windows, Türkiye only.

  1. Unpack

    Unpacks itself twice.

    AES → stage2.jar · RC4 → stage 3
  2. Check

    Checks the machine is worth it.

    RAM · CPU · not Windows Server
  3. Continues only in Türkiye.

    ip-api.com
  4. Asks for admin, looks for antivirus.

    downloads only if none runs
  5. Persist

    Makes itself permanent.

    scheduled task · REGEDIT · 30 s
  6. Fetches Tor, checks the circuit.

    torproject.org · 127.0.0.1:9050
  7. Control

    Calls home over Tor.

    …nhqd.onion : 49152 / 49153
  8. Waits for eleven commands.

    screenshot · DDoS · kill · shutdown
Command server 4ufbg…nhqd.onion Upload server 42dtw…rvyd.onion Build 5.3.0.2.F.0

Malicious. SoupDealer, three-stage Java loader. Remote access trojan over Tor.

Big Bro, the analyst mascot, and the Agent with his blaster. A small red intruder sneaks in, the Agent's scanner stops it mid-step, a glass sandbox closes around it and Big Bro studies it through his monocle.

Threat.Zone

Holistic malware analysis.

Threat.Zone's sandbox supports Windows, Linux, macOS and Android. Advanced static analysis, emulation and hypervisor-level detection give the highest level of threat detection, and its anti-evasion tactics make it thorough where agent-based sandboxes get spotted. It runs on-premise, in a private tenant or in the cloud.

Explore Threat.Zone Deployment options

Controllers

  • Extension Check
  • File Size Check

Modules

  • Static Scanner

Modules

  • CDR

HookMesh

Freedom to design your own workflows.

HookMesh is a flexible malware protection platform that connects to your existing security tools through its API. Its automated workflows coordinate every file-security product you run, and built-in CDR neutralizes sophisticated threats before they reach the network.

Explore HookMesh

Which door does it use?

Malwation stands in the corridor. Pick the door your files come through and see what happens behind it.

  • Mail

    Attachments, from anyone who can guess an address.

    CDR rebuilds every attachment at the gateway; the sandbox opens what CDR cannot.

    Email gateway security
  • File shares

    Whatever a colleague or a partner drops in.

    Neutralised at the point of entry, before the share fans it out.

    File sharing security
  • Upload forms

    CVs, invoices and support tickets, from the open web.

    Sanitised in real time instead of trusted.

    Web upload security

Also: Automated Malware Analysis, Malware Analysis Lab.

Don't take our word for it.

Three people who analyse malware for a living, on the platform they use.

Threat Zone is by far my favorite malware analysis platform. Its agent-less design works very well against sandbox-aware malware. Plus, it is a cost-effective solution compared to competitors, providing top-notch quality without breaking the bank.

Ege BalcıThreat Intelligence Division Manager

Most products use agents in their sandboxes, which are easily detected by malware, leading to failed executions. Malwation offers a stealthy analysis environment, allowing me to identify new variants swiftly and significantly reducing the time needed for analysis.

Robin DimyanoğluSecurity Engineering Manager

Threat.Zone quickly creates the MITRE ATT&CK map by using the indicators on my samples. The CSI module provides a specialized investigation environment with essential tools and saves a lot of time for me.

Numan TurleCyber Security Researcher

The people who build the platform are on the site too.

Meet the team

What Malwation stands for.

A team of cybersecurity professionals, researchers and engineers who develop the tools first and talk about them second. Four things hold across everything we ship.

Who we are
  1. Partner-first

    Our clients are at the heart of everything we do. We listen to their needs, understand their challenges, and tailor our solutions to exceed their expectations.

  2. Global

    Cybersecurity knows no borders. We collaborate with organizations worldwide so the benefits of our expertise reach the global community.

  3. Always learning

    In the dynamic world of cybersecurity, knowledge is power. We invest in research, development, and continuous learning to stay at the forefront of the field.

  4. Ethical

    We operate with integrity and ethical responsibility, respecting the privacy and security of individuals and organizations.