Prevention Methods of Virtual Machine Environment Recognition by Malware

Annisa Rifky Zulmeika, Marcellinus David Arel Bagjasantosa, Setia Juli Irzal Ismail, Hendrawan Hendrawan · 2024

Virtual Machine (VM) environment recognition or Anti-virtual machine (anti-VM) is one of the strategies employed by malware to evade detection. Virtual machines are frequently used for dynamic malware analysis. Using anti-VM techniques, malware can detect the presence of a VM and alter its behavior accordingly. To address this challenge, an effective approach involves first identifying the specific anti-VM techniques used by the malware, and then building protection within the VM to prevent malware from obscuring its actions. Anti-Vmtechniques typically search for indicators of a virtualized environment. These parameters include specific parameters such as the filesystem structure, running processes, and Windows Management Instrumentation (WMI). When malware detects these parameters, it may hide its functionality to evade detection. In this paper, we present a study on anti-VM techniques and describe the development of a tool designed to resist the anti-VM techniques on VirtualBox. This tool was implemented using PowerShell scripts and compiled into an executable (.exe) file. We tested the tool with well-known anti-VM detection programs, SEMS and Pafish. The results demonstrate that this tool can successfully mask several VM artifact parameters and prevent malware from recognizing the virtual environment.

Read the paper · More papers on PaperTik