VM Detection Methods in Malware | G DATA
Summary
We found that at least 2.77 % of analysed binaries were using at least one method strongly indicating the use of VM detection. At the first glance this does not seem much, but it should be noted that we could only detect the use of certain functions with their respective input values, but not if this was the malware’s actual intention. Both variants retrieve general information about the CPU and are valid methods for VM detection. Therefore, it is highly plausible that a much higher amount of samples was actually using virtual machine detection. If those checks return values lower than typical for a physical system, the chance of being executed on a VM is high.
Classifications
industries
No industries detected
applications
Networking and Cloud
AskAI Classifications
Labels
No AI classifications detected