Malware Classification and Customized Pattern Matching
Well over 100,000 malware variants are released into the wild each day, and while the samples themselves may be unique, the behaviors they exhibit can give them away through advanced pattern matching and heuristic analysis.
The Malware Analyzer G2 (MAG2) uses behavior-based malware classification patterns – not code-based signatures – to flag detected system events based on potential malicious activity. Patterns form the core basis of MAG2’s embedded intelligence and provide risk scoring based on criteria determined by Norman Shark’s malware analysts and a customer’s own unique criteria.
Patterns are used with both the SandBox and the IntelliVMs and include anti-VM (virtual machine) detection patterns. Patterns cover everything from generic malicious behavior (i.e. creating files, modifying registry keys) to family-specific behavior patterns (i.e. banking Trojans, keyloggers). The Malware Analyzer G2 reports all of the patterns that “triggered” during an analysis run based on the behavior exhibited by a particular sample. These combinations of indicators can be used by the customer for further malware classification into families based on related behavioral characteristics. The highest scoring triggered pattern determines the overall risk score.
Detects Polymorphic Binaries
Because they look for behavior and not code signatures or hash values, Norman Shark’s malware detection patterns are highly resistant to polymorphic binaries, new malware variations with equivalent instruction sequences where each variant carries its own signature and hash value. Polymorphs are designed to evade traditional signature-based detection mechanisms, but the Malware Analyzer G2 records events directly from the kernel and thus patterns match against kernel-level events which are extremely difficult for malware to evade.
Continuously Updated by Malware Classification Experts
Norman Shark has an experienced malware classification and analysis team that develops and maintains an updated set of efficient patterns optimized for analysis and detection of the latest cyber threats collected, reported and analyzed in our malware classification lab.


