« Leouncia - Yet Another Backdoor - Part 2 | Main | OMG-WTF-PDF Dénouement »

2011.01.27

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef0148c7ffdac3970c

Listed below are links to weblogs that reference The Dead Giveaways of VM-Aware Malware :

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Many of these Anti-detection methods are indeed very old, there's is really nothing new about any of these, and the ProductId detection for Anubis is useless aswell, as it have plenty of different ones (Try it yourself, upload a sample that printf()'s the ProductId and upload it a few times, you will see that Anubis randomizes the ProductId

Other sandboxes probably does this aswell.

Either way none of this is a new concept and my guess is that it is a RAT or similar (Like Bifrost) that have been coded by script kiddies.

Is the exe made in VB or .NET by any chance?

Great article as always, Atif.

Some of these tricks does not work already. They worked few years ago.

I am surprised that top malware list given by FireEye and Microsoft and thousands of ThreatExpert reports links are not enough for you. Why do not you come up with a counter list even of a fraction of the above mentioned data to prove your case?

If you think that Rebhip evasion techniques were able to stop AV industry, you can see the detection rate here:

http://www.virustotal.com/file-scan/report.html?id=f854a28eff3f85f96f8f1d7f281c3d072098534448000d49e289b73d5e650b17-1278356440

Anyways, I respect your freedom of speech right just like I do for “advanced_comentator” who is saying malware authors the brave guys and AV industry on a whole bad money suckers.

Really? You just complained of fud based on a claim of no data, but provide no data to make your own. Flimflam.
Ever take a real look at what doesn't run on TE? Can't tell from this writeup if you did.

Nice write-up. I guess I need to make my own proprietary VM. I don't have the time to disassemble that much anymore. It seems like the easiest way to defeat automated analysis though, is to simply wait for a specific user action to do something malicious.

>how the bad buys
>bad buys
Why AV companies always mixing truth? They are not "bad guys", they are good and brave guys. Trying to return their money from fat and dirty capitalists. Who are bad guys then? Answer is AV industry. They can't protect users from real attacks, such as stuxnet or conficker, just doing their PR and sucking money from innocent users.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.