Detecting Virtual Environment Artefacts
Created the Monday 11 March 2019. Updated 4 months, 3 weeks ago.
Qemu registers some artifacts into the registry. A malware can detect the Qemu installation with a look at the registry key
HARDWARE\\DEVICEMAP\\Scsi\\Scsi Port 0\\Scsi Bus 0\\Target Id 0\\Logical Unit Id 0 with the value of
Identifier and the data of
HARDWARE\\Description\\System with a value of
SystemBiosVersion and data of
The VirtualBox Guest addition leaves many artifacts in the registry. A search for
VBOX in the registry might find some keys.
The VMware installation directory
C:\\Program Files\\VMware\\VMware Tools may also contain artifacts, as can the registry. A search for VMware in the registry might find some keys that include information about the virtual hard drive, adapters, and virtual mouse.
VMware leaves many artefacts in memory. Some are critical processor structures, which, because they are either moved or changed on a virtual machine, leave recognisable footprints. Malware can search through physical memory for the strings VMware, commonly used to detect memory artifacts.
The resources provided below are associated links that will give you even more detailed information and research on current evasion technique. It is important to note that, while these resources may be helpful, it is important to exercise caution when following external links. As always, be careful when clicking on links from unknown sources, as they may lead to malicious content.