Methods of masking the virtual environment
More in Malware
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
During malware analysis, you may encounter samples that will not function fully in a virtual environment. This is because they implement special mechanisms that check the environment in which the sample is running.
Upon detecting that it is running in a virtual environment, the malware may either cease operation or masquerade as legitimate software.
😂 However, such samples can be attempts to deceive — to “convince” them that they are running on a physical device.
To do this, we need just one properly configured virtual machine (VM) that will conceal its virtual nature. Let’s look at a couple of methods for such configuration.
Method 1️⃣
The first method is the publicly available
VmwareHardenedLoader. You need to edit the .vmx file and change the VM’s MAC address to any that does not start with 00:05:69, 00:50:56, 00:1C:14, 00:0С:29.According to the documentation for this tool, add the following properties to the .vmx file:
hypervisor.cpuid.v0 = "FALSE"
board-id.reflectHost = "TRUE"
hw.model.reflectHost = "TRUE"
serialNumber.reflectHost = "TRUE"
isolation.tools.getPtrLocation.disable = "TRUE"
isolation.tools.setPtrLocation.disable = "TRUE"
isolation.tools.setVersion.disable = "TRUE"
isolation.tools.getVersion.disable = "TRUE"
monitor_control.disable_directexec = "TRUE"
monitor_control.disable_chksimd = "TRUE"
monitor_control.disable_ntreloc = "TRUE"
monitor_control.disable_selfmod = "TRUE"
monitor_control.disable_reloc = "TRUE"
monitor_control.disable_btinout = "TRUE"
monitor_control.disable_btmemspace = "TRUE"
monitor_control.disable_btpriv = "TRUE"
monitor_control.disable_btseg = "TRUE"
monitor_control.restrict_backdoor = "TRUE"
smbios.reflectHost = "TRUE"
SMBIOS.noOEMStrings = "TRUE"
scsi0:0.productID = "Your value"
scsi0:0.vendorID = "Your value"
ethernet0.address = "new mac address"
Code language: YAML (yaml)If, upon starting the VM, the MAC address changes to one generated by VMware, edit it directly in the GUI.
Next, you need to run the installation script
install.bat with administrator privileges in the configured VM. After that, you can begin debugging. Now the VM should not be visible to the malware sample. It is important to remember that vmtools should not be installed. If this option did not work, there is another one.
Method 2️⃣
It is more complex, but also more reliable. The approach is the same — configuring the VM, but in this case it is also necessary to patch the BIOS.
The following steps must be performed:
1. When creating a new VM, it is not recommended to immediately select the installation ISO file, otherwise
Windows Easy Install will be activated, which will install vmtools. 2. To make the decoy OS a “worthy” victim for the malware, it is necessary to allocate at least 128 GB of disk space.
3. In
Firmware Type, select BIOS.4. In the hardware configuration settings, be sure to check the
Virtualize Intel VT-x/EPT or AMD-V/RVI checkbox5. As in the first case, change the MAC address to any except those typical for VMware
6. Then add the installation ISO file. Don’t forget about vmtools — they should not be installed.
7. After that, it is necessary to patch the BIOS ROM.
The VMware BIOS ROM contains strings related to VMware and virtualization. They need to be removed and replaced with some of your own. The BIOS ROM file is located in the folder
C:\Program Files (x86)\VMware\VMware Workstation\x64. When doing so, the file should be edited with a special tool —
Phoenix BIOS Editor, so as not to alter the file’s internal checksums. Open the file in the editor, find the window with DMI Strings, and change the values so that they do not contain “VMware” or “Virtual Platform”.After that, you need to build the patched BIOS via
File → Build BIOS and save it somewhere without deleting the original.8. In the folder where the VM is stored, you need to find the .vmx file. Add the path to the patched BIOS ROM file to it:
bios440.filename = "D:\<path_to_your_bios_file>\BIOS.440.PATCH.ROM", as well as the same settings as in method 1, except for the last four lines.Done. You can start the virtual OS. Now the malware will not realize it is running on a VM and will function as it should.
#tips #malware
@ptescalator
More in Malware
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…





