How Malware Detect Virtual Machines

Discussion in 'other security issues & news' started by Rasheed187, Nov 25, 2006.

Thread Status:
Not open for further replies.
  1. Rasheed187

    Rasheed187 Registered Member

  2. Rasheed187

    Rasheed187 Registered Member

    This is interesting but would it really work, I wonder. :rolleyes:

    http://weblog.infoworld.com/virtualization/archives/2006/11/virtual_machine_1.html
     
  3. Devil's Advocate

    Devil's Advocate Registered Member

  4. EsoxLucius

    EsoxLucius Registered Member

    That's why:

     
  5. Mrkvonic

    Mrkvonic Linux Systems Expert

    Hello,
    Very simple - you run a tool in virtual machine - if it refuses to cooperate, you never install it natively.
    Mrk
     
  6. GS2

    GS2 Registered Member

    Or just use a real test box, instead of a VM (obviously not your everyday machine)
     
  7. Devil's Advocate

    Devil's Advocate Registered Member

    Oh right, I forgot everyone here including Rasheed are
    analysts. :rolleyes:
     
  8. Rasheed187

    Rasheed187 Registered Member

    Good one DA, but of course I meant it´s bad news for the analysts, but even for us amateurs who like to fool around with malware sometimes. But according to the article, some malware will simply refuse to run, but what if apps can act like they are non malicious when run in a virtual machine, does this stuff exist yet? :blink:
     
  9. Rasheed187

    Rasheed187 Registered Member

  10. TNT

    TNT Registered Member

    I haven't seen one acting "non malicious" (rather, I've seen quite a bit simply not run at all). But it's very possible and I don't see any reason why malware authors wouldn't have thought about writing something like this.
     
  11. Rasheed187

    Rasheed187 Registered Member

    Well, if you read the article, Sophos actually thinks that this malware might already exist. :rolleyes:

     
  12. Rasheed187

    Rasheed187 Registered Member

  13. Inspector Clouseau

    Inspector Clouseau AV Expert

    There are a few *1000's* bots (RBots etc) which don't run under virtual environment. Moreover, there are runtime packers and crypters which having this functionality included. Themida for instance.

    See here: http://vil.nai.com/vil/content/v_139328.htm
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice