A forum for reverse engineering, OS internals and malware analysis 

Search found 124 matches: AntiVM

Searched query: antivm

 Go to advanced search

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Mon Oct 22, 2012 6:41 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

... For example old Pragma TDSS droppers were checking system location (by system locale) and if they running in exUSSR zone - they quits. But its not antivm.

Re: VirtualBox Anti-AntiVM

 by kmd ¦  Mon Oct 22, 2012 6:27 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

thx for update. is it enough strong for malware detection bypass?

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Mon Oct 22, 2012 2:55 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

Thank you for this thread. I've been trying to do this without success. I'm not 100% sure but I think the hard disk is set up as IDE, not AHCI. How can I change this without being able to go into a BIOs environment? Some more examples would be appreciated. What exactly you tried? You can add new HD...

Re: VirtualBox Anti-AntiVM

 by thisisu ¦  Mon Oct 22, 2012 12:12 am ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

Thank you for this thread.

I've been trying to do this without success. I'm not 100% sure but I think the hard disk is set up as IDE, not AHCI. How can I change this without being able to go into a BIOs environment?
Some more examples would be appreciated.

Re: VirtualBox Anti-AntiVM

 by EP_X0FF ¦  Sun Oct 21, 2012 3:19 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

As requested, for x64 v4.2.2.281494. For more info refer to previous posts.

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by EP_X0FF ¦  Sun Oct 21, 2012 10:58 am ¦  Forum: Malware ¦  Topic: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco) ¦  Replies: 149 ¦  Views: 169206

kmd wrote:@EP_XOFF
vbox update today for 4.2.2, can you update dlls?
Yes, later. VBox Anti-AntiVM related posts moved in separate topic.

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by kmd ¦  Fri Oct 19, 2012 9:15 am ¦  Forum: Malware ¦  Topic: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco) ¦  Replies: 149 ¦  Views: 169206

... spies and collecting info for self-promo company this guy loves to do. look at his blogpost again - what he actually did or may be found new? WMI antivm? nope. phaeton posted here MUCH more and MUCH detailed. as well as how to bypass this. figured out this is just updated old rootkit and did this ...

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by EP_X0FF ¦  Thu Oct 18, 2012 12:01 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

... for anything? im gonna now use vbox as primary vm. Physical machine always better. However you can setup VM that will be protected from 99.9% of antivm tricks seen in ITW malware up to date. I'm not using VirtualBox as primary VM but I have it customized too. Few simple steps to configure VirtualBox. ...

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by EP_X0FF ¦  Wed Oct 17, 2012 5:23 pm ¦  Forum: Malware ¦  Topic: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco) ¦  Replies: 149 ¦  Views: 169206

... or SST.C,D,E,F etc. If Damballa think different - then give us a proof not BS article as it did. Also 0x16/7ton did really good job revealing all AntiVM contents of this dropper, so we need to thank him.

Re: Rootkit MaxSS (alias TDSS, SST, Alureon.FE, Olmasco)

 by EP_X0FF ¦  Wed Oct 17, 2012 4:23 pm ¦  Forum: Tools/Software ¦  Topic: VirtualBox Anti-AntiVM ¦  Replies: 63 ¦  Views: 214173

... are installed. This is important part of any malware research - never use any kind of VM tools. Next configure DMI information to fool rootkit antivm checking. For vbox: VBoxManage setextradata "My VM" "VBoxInternal/Devices/pcbios/0/Config/DmiBIOSVendor" "Gigabyte" (any vendor but not Microsoft/Virtual ...

  • 1
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13