<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"
	xml:lang="en-us">
	<title>Comments on The Dead Giveaways of VM-Aware Malware </title>
	<subtitle></subtitle>
	<link rel="self" type="application/atom+xml" title="Comments on The Dead Giveaways of VM-Aware Malware " href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware/comments/atom.xml" />
	<link rel="alternate" type="text/html" title="The Dead Giveaways of VM-Aware Malware " href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html"/>
	<generator uri="http://www.typepad.com/">TypePad</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<updated>2011-01-25T21:29:01Z</updated>
	<author>
		<name>FireEye</name>
		<uri>http://blog.fireeye.com/research/</uri>
	</author>
	<id>tag:typepad.com,2003:http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware/comments/atom.xml/</id>
    
		<entry>
			<title>sneino commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="this is good for older threats. the next wave of threats will be far more sophisticated. Targeted attacks/apts currently use..." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef014e865bc0e8970d#comment-6a00d835018afd53ef014e865bc0e8970d" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef014e865bc0e8970d</id>
			<published>2011-02-27T08:09:25Z</published>
			<updated>2011-02-27T08:09:25Z</updated>
			<author>
				<name>sneino</name>
                
			</author>
			<summary>this is good for older threats. the next wave of threats will be far more sophisticated. Targeted attacks/apts currently use...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;this is good for older threats. the next wave of threats will be far more sophisticated. Targeted attacks/apts currently use far more complex techniques for evasion, such as opcode and api emulation weaknesses in sandbox/VMM/emulators. These are very difficult to detect, and some infeasible to notice without manual analysis. Additionally, zero day vulnerabilities are being used to evade. tools. Imagine running IDA or IDA w/ Hexrays and during disassembly compromising your system... imagine the box you use to sandbox and protect your network being compromised via zero day and sandbox escape, now you have a new threat channel, and its even more covert than a standard attack against an end node.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Roger commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="Many of these Anti-detection methods are indeed very old, there&#39;s is really nothing new about any of these, and the..." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0148c81aec2d970c#comment-6a00d835018afd53ef0148c81aec2d970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0148c81aec2d970c</id>
			<published>2011-01-28T18:24:48Z</published>
			<updated>2011-01-28T18:24:48Z</updated>
			<author>
				<name>Roger</name>
                
			</author>
			<summary>Many of these Anti-detection methods are indeed very old, there&#39;s is really nothing new about any of these, and the...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;Many of these Anti-detection methods are indeed very old, there&amp;#39;s is really nothing new about any of these, and the ProductId detection for Anubis is useless aswell, as it have plenty of different ones (Try it yourself, upload a sample that printf()&amp;#39;s the ProductId and upload it a few times, you will see that Anubis randomizes the ProductId&lt;/p&gt;

&lt;p&gt;Other sandboxes probably does this aswell.&lt;/p&gt;

&lt;p&gt;Either way none of this is a new concept and my guess is that it is a RAT or similar (Like Bifrost) that have been coded by script kiddies.&lt;/p&gt;

&lt;p&gt;Is the exe made in VB or .NET by any chance?&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>James W commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="Great article as always, Atif." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0148c816d15e970c#comment-6a00d835018afd53ef0148c816d15e970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0148c816d15e970c</id>
			<published>2011-01-28T07:26:13Z</published>
			<updated>2011-01-28T07:26:13Z</updated>
			<author>
				<name>James W</name>
                
			</author>
			<summary>Great article as always, Atif.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;Great article as always, Atif.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Nikolay commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="Some of these tricks does not work already. They worked few years ago." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0148c816b315970c#comment-6a00d835018afd53ef0148c816b315970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0148c816b315970c</id>
			<published>2011-01-28T07:03:12Z</published>
			<updated>2011-01-28T07:03:12Z</updated>
			<author>
				<name>Nikolay</name>
                
			</author>
			<summary>Some of these tricks does not work already. They worked few years ago.</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;Some of these tricks does not work already. They worked few years ago.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Atif Mushtaq commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="I am surprised that top malware list given by FireEye and Microsoft and thousands of ThreatExpert reports links are not..." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0148c816664a970c#comment-6a00d835018afd53ef0148c816664a970c" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0148c816664a970c</id>
			<published>2011-01-28T06:06:58Z</published>
			<updated>2011-01-28T06:06:58Z</updated>
			<author>
				<name>Atif Mushtaq</name>
                <uri>http://blog.fireeye.com</uri>
			</author>
			<summary>I am surprised that top malware list given by FireEye and Microsoft and thousands of ThreatExpert reports links are not...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;I am surprised that top malware list given by FireEye and Microsoft and thousands of ThreatExpert reports links are not enough for you. Why do not you come up with a counter list even of a fraction of the above mentioned data to prove your case?&lt;/p&gt;

&lt;p&gt;If you think that Rebhip evasion techniques were able to stop AV industry, you can see the detection rate here:&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://www.virustotal.com/file-scan/report.html?id=f854a28eff3f85f96f8f1d7f281c3d072098534448000d49e289b73d5e650b17-1278356440&quot; rel=&quot;nofollow&quot;&gt;http://www.virustotal.com/file-scan/report.html?id=f854a28eff3f85f96f8f1d7f281c3d072098534448000d49e289b73d5e650b17-1278356440&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Anyways, I respect your freedom of speech right just like I do for “advanced_comentator” who is saying malware authors the brave guys and AV industry on a whole bad money suckers.&lt;br /&gt;
&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>ok commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="Really? You just complained of fud based on a claim of no data, but provide no data to make your..." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0147e20d1699970b#comment-6a00d835018afd53ef0147e20d1699970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0147e20d1699970b</id>
			<published>2011-01-28T05:38:07Z</published>
			<updated>2011-01-28T05:38:07Z</updated>
			<author>
				<name>ok</name>
                <uri>http://WWW.yahoo.con</uri>
			</author>
			<summary>Really? You just complained of fud based on a claim of no data, but provide no data to make your...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;Really? You just complained of fud based on a claim of no data, but provide no data to make your own. Flimflam.&lt;br /&gt;
Ever take a real look at what doesn&amp;#39;t run on TE? Can&amp;#39;t tell from this writeup if you did.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>Mark D. Adams commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="Nice write-up. I guess I need to make my own proprietary VM. I don&#39;t have the time to disassemble that..." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0147e20cf51f970b#comment-6a00d835018afd53ef0147e20cf51f970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0147e20cf51f970b</id>
			<published>2011-01-28T05:09:41Z</published>
			<updated>2011-01-28T05:09:41Z</updated>
			<author>
				<name>Mark D. Adams</name>
                <uri>http://myblog.org</uri>
			</author>
			<summary>Nice write-up. I guess I need to make my own proprietary VM. I don&#39;t have the time to disassemble that...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;Nice write-up. I guess I need to make my own proprietary VM. I don&amp;#39;t have the time to disassemble that much anymore. It seems like the easiest way to defeat automated analysis though, is to simply wait for a specific user action to do something malicious.&lt;/p&gt;</content>
		</entry>
	
		<entry>
			<title>advanced_comentator commented on &#39;The Dead Giveaways of VM-Aware Malware &#39;</title>
			<link rel="alternate" type="text/html" title="&gt;how the bad buys &gt;bad buys Why AV companies always mixing truth? They are not &quot;bad guys&quot;, they are good..." href="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html?cid=6a00d835018afd53ef0147e20cea8c970b#comment-6a00d835018afd53ef0147e20cea8c970b" />
			<id>tag:typepad.com,2003:6a00d835018afd53ef0147e20cea8c970b</id>
			<published>2011-01-28T05:01:33Z</published>
			<updated>2011-01-28T05:01:33Z</updated>
			<author>
				<name>advanced_comentator</name>
                
			</author>
			<summary>&gt;how the bad buys &gt;bad buys Why AV companies always mixing truth? They are not &quot;bad guys&quot;, they are good...</summary>
			<content type="html" xml:base="http://blog.fireeye.com/research/2011/01/the-dead-giveaways-of-vm-aware-malware.html">&lt;p&gt;&amp;gt;how the bad buys&lt;br /&gt;
&amp;gt;bad buys&lt;br /&gt;
Why AV companies always mixing truth? They are not &amp;quot;bad guys&amp;quot;, they are good and brave guys. Trying to return their money from fat and dirty capitalists. Who are bad guys then? Answer is AV industry. They can&amp;#39;t protect users from real attacks, such as stuxnet or conficker, just doing their PR and sucking money from innocent users.&lt;/p&gt;</content>
		</entry>
	
</feed>

<!-- ph=1 -->