Detecting Virtual Environment Artefacts

Created the Monday 11 March 2019. Updated 1 year, 1 month ago.

Qemu registers some artifacts into the registry. A malware can detect the Qemu installation with a look at the registry key HARDWARE\\DEVICEMAP\\Scsi\\Scsi Port 0\\Scsi Bus 0\\Target Id 0\\Logical Unit Id 0 with the value of Identifier and the data of QEMU or HARDWARE\\Description\\System with a value of SystemBiosVersion and data of QEMU.

The VirtualBox Guest addition leaves many artifacts in the registry. A search for VBOX in the registry might find some keys.

The VMware installation directory C:\\Program Files\\VMware\\VMware Tools may also contain artifacts, as can the registry. A search for VMware in the registry might find some keys that include information about the virtual hard drive, adapters, and virtual mouse.

VMware leaves many artefacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognisable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts.


Technique Identifier

U1332


Code Snippets

Detection Rules

Additional Resources

External Links

The resources provided below are associated links that will give you even more detailed information and research on current evasion technique. It is important to note that, while these resources may be helpful, it is important to exercise caution when following external links. As always, be careful when clicking on links from unknown sources, as they may lead to malicious content.

Matching Samples 10 most recent

Sample Name Matching Techniques First Seen Last Seen
Tirexdel v1.1.1.exe 4 2024-11-17 8 hours, 15 minutes ago
KnightOnLine.exe 7 2024-11-17 12 hours, 11 minutes ago
chelentano.exe 5 2024-11-16 1 day, 20 hours ago
Help Verdict pls - URLs IPs ... shared group - 07.28.24.txt 3 2024-11-15 2 days, 8 hours ago
DOSSHOTSDEVODKA.arn 3 2024-11-15 2 days, 9 hours ago
System.Transactions.dll 10 2024-11-15 2 days, 10 hours ago
System.Printing.dll 6 2024-11-15 2 days, 10 hours ago
System.EnterpriseServices.dll 9 2024-11-15 2 days, 10 hours ago
PresentationCore.dll 4 2024-11-15 2 days, 10 hours ago
NAPCRYPT.DLL 7 2024-11-15 2 days, 10 hours ago
View All

Sleeping Alien

Subscribe to our Newsletter

Don't miss out on the latest and greatest updates from us! Subscribe to our newsletter and be the first to know about exciting content and future updates.