Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Anti-VM - VM identifiers in disk enums #191

Closed
recvfrom opened this issue Sep 5, 2019 · 3 comments · Fixed by #220
Closed

Anti-VM - VM identifiers in disk enums #191

recvfrom opened this issue Sep 5, 2019 · 3 comments · Fixed by #220

Comments

@recvfrom
Copy link
Contributor

recvfrom commented Sep 5, 2019

From [1], disk enums in HKLM\System\CurrentControlSet\Services\Disk\Enum sometimes contains strings like Virtual, VMW, or Vbox, which some malware uses as an anti-VM check. Would it be worth also checking for this in al-khaser?

[1] https://cofense.com/kutaki-malware-bypasses-gateways-steal-users-credentials/

@Waterman178
Copy link

good idea

@recvfrom
Copy link
Contributor Author

Another example [2] - Smokeloader checks System\CurrentControlSet\Services\Disk\Enum\IDE and System\CurrentControlSet\Services\Disk\Enum\SCSI for qemu, virtio, vmware vbox or xen

[2] https://research.checkpoint.com/2019-resurgence-of-smokeloader/

@ayoubfaouzi
Copy link
Owner

Hello @recvfrom

Thanks ! I will add those in the next release.

Cheers.

recvfrom added a commit to recvfrom/al-khaser that referenced this issue Oct 28, 2020
ayoubfaouzi added a commit that referenced this issue Oct 28, 2020
Fix #191 - Add Anti-VM disk enum registry checks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants