Malware analysis EU-developed

VMRay Platform

Analyzes suspicious files, URLs and emails with layered sandbox techniques, returning behavioral findings, verdict context and extracted indicators for responders.

By VMRay GmbH · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
VMRay GmbH
Recorded country
Germany
Product model
Commercial
Deployment
Self-hosted / SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

VMRay says its founders developed pioneering sandbox technology during doctoral work in Bochum and founded VMRay GmbH there in 2013; the present platform has global staff and customers.

Reported capabilities

  • Malware and phishing sandbox analysis
  • Behavioral findings and extracted IOCs
  • Cloud or on-premises product plans

Scope and limits

Current VMRay Platform is offered through DeepResponse, FinalVerdict and TotalInsight plans; VMRay Analyzer is a discontinued legacy plan and is not a separate current entry. Product pricing/trial pages establish commercial delivery, but no full platform end-user license was publicly verified. Cloud region or sovereignty claims should not be assumed for every plan.

Inspect the research evidence 6 source observations
  1. identity / capabilities

    Official platform site describes sandbox-based malware and phishing analysis for SOC, CERT and CTI teams, with integrations and API access.

    Read source
  2. deployment

    Vendor FAQ explicitly offers VMRay Cloud and On-Premises, and documents manual WebUI, mailbox, REST API and connector submission paths.

    Read source
  3. origin / country

    Vendor history says the founders completed doctoral work at Ruhr University Bochum on sandbox technology and founded VMRay GmbH in 2013; the company lists Bochum and Boston offices.

    Read source
  4. license

    Vendor pricing page solicits commercial product and pricing requests; reviewed public pages did not provide complete end-user license text for the current platform.

    Read source
  5. maintenance / capabilities

    Dated 9 April 2026 Platform 2026.2.0 release describes recursive malware analysis, improved reporting and new Cloud controls; vendor release claims are not independent effectiveness evidence.

    Read source
  6. identity

    Vendor says legacy Analyzer was discontinued and replaced by current plans built on the shared VMRay Platform.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

MISP Integration

VMRay's separately deployed vmray-misp-feed script periodically converts platform analysis results to MISP events. Requires VMRay API access and MISP access to the generated feed; report attachments, tags and IOC-only export are configurable.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files