View Single Post
  #3  
Old 03-29-2010, 18:58
Silkut Silkut is offline
Friend
 
Join Date: Jun 2006
Posts: 24
Rept. Given: 12
Rept. Rcvd 2 Times in 2 Posts
Thanks Given: 1
Thanks Rcvd at 1 Time in 1 Post
Silkut Reputation: 2
Hi,

metr0, I believe the source of those tips are this blog hXXp://vrt-sourcefire.blogspot.com/2009/10/how-does-malware-know-difference.html

I think defeating VM detection goes through suming up all the detection techniques and finding a workaround for each of them.

EvilCry got a C file on his blog, referencing lots of functions to detect emulation/sandbox/virtualization, maybe some ideas to pick up there.

Ed Skoudis also wrote something about VM detection thwarts, for SANS Institute I believe.
Reply With Quote