A forum for reverse engineering, OS internals and malware analysis 

Search found 124 matches: AntiVM

Searched query: antivm

 Go to advanced search

Re: Max++ fails to infect Win7 x86 ?

 by EP_X0FF ¦  Thu Nov 17, 2011 1:18 am ¦  Forum: Newbie Questions ¦  Topic: Max++ fails to infect Win7 x86 ? ¦  Replies: 2 ¦  Views: 4264

Try something like WinXP + VBox 4.x. It should work, if dropper has no antivm code. Or use real machine instead.

Re: NgrBot (aka Win32/Dorkbot.gen!A)

 by EP_X0FF ¦  Sat Nov 05, 2011 8:02 am ¦  Forum: Malware ¦  Topic: NgrBot (aka Win32/Dorkbot.gen!A) ¦  Replies: 71 ¦  Views: 79663

Dorkbot (crypter TensilCrypt? with AntiVM and multiple process restarting feature)

http://www.virustotal.com/file-scan/rep ... 1320478396

dropper and unpacked in attach

Re: Dropper/Win32.VB

 by EP_X0FF ¦  Fri Nov 04, 2011 3:00 pm ¦  Forum: Malware ¦  Topic: Dropper/Win32.VB ¦  Replies: 3 ¦  Views: 4364

Trojan Muldrop crypted by iCrypt Classic v4.4 with AntiVM GetModuleHandleW sbiedll.dll VIRTUAL HD Sleep GetVolumeInformationW QEMU HARDDISK VMWARE VIRTUAL IDE HARD DRIVE CreateFileW \\.\PhysicalDrive0 and then packed with UPX, internally something ...

Re: Rootkit TDL 4 (alias TDSS, Alureon.DX, Olmarik)

 by Julian ¦  Sun Oct 16, 2011 8:38 pm ¦  Forum: Malware ¦  Topic: Rootkit TDL 4 (alias TDSS, Alureon.DX, Olmarik) ¦  Replies: 595 ¦  Views: 654946

IDK what exactly does not working for Julian but it isn't antivm or something, because I've some of these posted samples in my vm repository. It is known that updated TDL4 may cause KB2506014 patched system unbootable. Dropper tries to infect MBR but ...

Re: Malware/Not classified

 by EP_X0FF ¦  Wed Oct 05, 2011 5:06 pm ¦  Forum: Malware ¦  Topic: Win32/Phorpiex (alias Phokace, Trik) ¦  Replies: 17 ¦  Views: 31709

... Trojan downloader Phokace with AntiVM. Payload hxxp://www.allezdax.com/images/m.exe (crypted and packed by MPRESS Worm:Win32/Phorpiex.B ) decrypted downloader, payload + decrypted ...

Re: Malware/Not classified

 by nullptr ¦  Tue Sep 27, 2011 5:14 am ¦  Forum: Malware ¦  Topic: Win32/Spatet ¦  Replies: 69 ¦  Views: 43609

... edit: TensilCrypt can throw an error due to AntiVM. Just search for (VIRTUAL, VBOX, Sbie.dll etc) strings and change them. All in attachment.

Re: Fraud/Rouge software

 by EP_X0FF ¦  Thu Jun 16, 2011 11:35 am ¦  Forum: Malware ¦  Topic: Fraud/Rouge software ¦  Replies: 115 ¦  Views: 127017

... GUI http://img690.imageshack.us/img690/8821/27683203.th.gif Has antivm and anti-debugging on board (likely part of crypter code). Perfect example of Matryoshka (crypter+UPX->crypter+UPX) All original + unpacked in ...

Windows XP Recovery

 by EP_X0FF ¦  Fri May 27, 2011 3:05 pm ¦  Forum: Malware ¦  Topic: Fraud/Rouge software ¦  Replies: 115 ¦  Views: 127017

... hosted ZAccess sample). Muldrop, crypted then packed by UPX, payload it drops also crypted and packed by UPX. Uses IE injection. Dropper has AntiVM on board (VMWare, Virtual Box, Virtual PC). In attach original dropper and extracted payload. http://www.virustotal.com/file-scan/report.html?id=887487779c7331319e166ea97f15ecabd45daad50b6aa27833622b86de00602c-1306508426

Re: Trojan SpyEye (alias Pincav)

 by EP_X0FF ¦  Wed May 18, 2011 6:09 am ¦  Forum: Malware ¦  Topic: Trojan SpyEye (alias Pincav) ¦  Replies: 418 ¦  Views: 409709

... This SpyEye v1.3 more interesting. It has antivm on board (probably part of skiddie crypter). Actually it looks for VmWare/VirtualPC/Sandbox/QEMU by checking specific registry keys, volume serial ...

Re: Malware/MSIL-BA

 by EP_X0FF ¦  Sat Apr 02, 2011 11:20 am ¦  Forum: Malware ¦  Topic: Backdoor CyberGate v1.07 ¦  Replies: 9 ¦  Views: 13415

... because they are internally ABSOLUTELY ALL the same (the only difference maybe - crypter used, some crypter adds additional features such as AntiVM and other sort of skiddie BS). As for VT results - fresh crypted malware (with fresh clean crypter used) will always fool all VirusTotal patients ...

  • 1
  • 9
  • 10
  • 11
  • 12
  • 13