Home > ParetoLogic Blogs > Malware Diaries > VirtualBox less and less effective for malware analysis
Reply
 
Thread Tools Display Modes
  #1  
Old 09-28-2009, 07:41 PM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default VirtualBox less and less effective for malware analysis

About 2 years ago, I switched from VMware to VirtualBox. There were mainly two reasons why:

- VirtualBox was free
- VMware was giving me poor results when analyzing samples (Virtualization detection)

Well, today VirtualBox is still free, but it seems to be plagued by the same problems as far as malware detecting the virtual environment.

Many samples will have a totally different behaviour when analzyed in a VM such as:

- do nothing
- delete themselves
- do a minor payload

It is quite tricky to detect if a sample is VM-aware, for the reasons outlined above. So, at the end of the day, we are missing out on some really prevalent samples that people will get infected with.

Take this rogue for example, Security Tool.

Under a VM, it does nothing; in a real PC it installs and runs just fine:

vbox1

vbox2

Does that explain why some of the big players are not detecting it? I'm refering to Kaspersky, Symantec, F-Secure, Panda?

vt

It looks like it's time to go back to the real machines for good.



Jerome Segura

Malware ID: 37e6447f055641903d1c17a11eb1b592.zip
Reply With Quote
  #2  
Old 09-28-2009, 07:44 PM
S!Ri S!Ri is offline
Junior Member
Join Date: Jul 2009
Posts: 6
Default

Quote:
It looks like it's time to go back to the real machines for good.
Or Patch/Crack the protection
Reply With Quote
  #3  
Old 09-29-2009, 03:43 PM
JSegura JSegura is offline
Editor
Join Date: Mar 2008
Posts: 51
Default

Quote:
Originally Posted by S!Ri View Post
Or Patch/Crack the protection
If you can do this programatically that would be great. But doing that for every sample manually would be pain staking!!
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use