LordNoteworthy / al-khaser

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
GNU General Public License v2.0
5.65k stars 1.15k forks source link

Anti-VM: Screen Resolution #216

Open Sqeegie opened 3 years ago

Sqeegie commented 3 years ago

While not a full-proof detection vector, using common default VM resolutions (I.e. 800x600 or 1024x768), could be a good test for default sandboxes.

https://www.bleepingcomputer.com/news/security/trickbot-malware-now-checks-screen-resolution-to-evade-analysis/

gsuberland commented 3 years ago

Appears there are a bunch of potential artifacts we can use here: