Uploading a suspicious file to a public multi-scanner or shared sandbox is often the fastest way to get a answer. It is frequently the wrong way to get your answer. The difference is not snobbery about tools. It is about who else sees the artefact, what the verdict actually means, and which decision you still cannot make when the bar chart comes back green or red.
What a public sandbox is good for
Public platforms earn their keep on commodity questions. If you have a hash that is already in wide circulation, no customer data inside the file, and you only need to know whether twenty vendors already call it a known family, a public lookup is rational. It is also rational as a first screen when the file is yours to share and the cost of leakage is close to zero.
What you give away when you upload
- The artefact itself: including any embedded documents, internal hostnames, tokens, or staging infrastructure the operator has not burned yet.
- The fact of your interest: other participants on that platform, including the operator of the malware, may see that this hash has been submitted from a new corner of the internet.
- A timestamp and telemetry: enough, in some cases, to tell an adversary that the campaign has been noticed.
None of that is theoretical tradecraft. It is the ordinary information-sharing model of those products. If the sample came off a government network, a law-firm file share, or a payment system, that model is usually incompatible with your duty of confidentiality.
What a public verdict does not tell you
A detection ratio is not a behaviour map. It will not tell you whether the sample beacons only after a specific user logs in, whether it has a kill-date, whether it stole the browser vault, or whether the EDR alert you already have is the same family or a second implant. It also cannot tell you to stand down. Zero detections is not a clean bill of health; it is “these engines did not match it today”.
A decision rule
Use a public lookup when all of the following are true: the file is yours to share; it is unlikely to contain other people’s data; you need only a commodity reputation signal; and you can accept the artefact becoming public. Use private analysis when any of the following are true: the sample may contain client or official information; it looks targeted or unique; you need indicators to hunt across the rest of the estate; you need a brief a board will trust; or you cannot prove a negative from a crowd-sourced score.
If you are already in an incident, skip the public upload entirely. Use Get incident help and keep the sample off the open internet until a responder has a channel for it.
What private analysis should still refuse to over-claim
A professional report should still say when it does not know. Attribution, completeness (“there is no other malware here”), and guaranteed eradication are not things a sandbox, public or private, can honestly sell. See malware analysis for how we separate observation from inference.
Sources
- Australian Signals Directorate, ransomware advice: official public guidance on not worsening an incident while you seek help.
- cyber.gov.au: current Australian government cyber threat and reporting material.
Accountability
Published by Cybersecurity Engineering Pty Ltd, trading as MalwareAnalysis.app. This is general guidance, not advice about your incident. A named expert profile will be attached once approved for publication. Review this page again after 5 March 2027, or sooner if official ASD or OAIC guidance changes.
Related: Malware analysis service · Evidence handling
Use the evidence in context
This article reflects understanding at its stated publication and review dates. It is general information, not advice about your specific incident, system or legal position.