4 ms·
Using a VM is the standard way to analyze malware. There is a threat, but its not considered to be significant at this point. If you were analyzing a malware sa
by phaus 9y ago
Using a VM is the standard way to analyze malware. There is a threat, but its not considered to be significant at this point. If you were analyzing a malware sample that you knew for a fact performed VM escape, you would run it in a VM on a system specifically designated for that purpose.
There are lots of ways that malware can detect the presence of a virtual environment, but part of reverse engineering malware involves defeating these mechanisms.
Here's just a few simple ways that malware can detect the presence of a VM:
- Size of the hard drive. (people frequently use smaller amounts of storage space for virtual environments).
- Presence of a debugger.
- Scanning for common analysis tools (regshot, process
monitor, ollydbg, etc.
- Processes associated with VMware
- Network connectivity (like we recently observed)
If anyone's interested in learning malware analysis, practical malware analysis is a great book for someone that's already decent at programming. I'd also recommend learning assembly pretty well before you get started.