VM Detection Methods in Malware | G DATA

General News

Summary

We found that at least 2.77 % of analysed binaries were using at least one method strongly indicating the use of VM detection. At the first glance this does not seem much, but it should be noted that we could only detect the use of certain functions with their respective input values, but not if this was the malware’s actual intention. Both variants retrieve general information about the CPU and are valid methods for VM detection. Therefore, it is highly plausible that a much higher amount of samples was actually using virtual machine detection. If those checks return values lower than typical for a physical system, the chance of being executed on a VM is high.

Classifications

industries
No industries detected
applications
Networking and Cloud

AskAI Classifications

Labels
No AI classifications detected

Linked Companies