
जंगली में उपयोग की जाने वाली सार्वजनिक मैलवेयर तकनीकें: वर्चुअल मशीन, एमुलेशन, डीबगर्स, सैंडबॉक्स का पता लगाना।

al-khaser एक PoC "मैलवेयर" एप्लिकेशन है जिसके अच्छे इरादे हैं और इसका उद्देश्य आपके एंटी-मैलवेयर सिस्टम का तनाव परीक्षण करना है। यह आम मैलवेयर चालों का एक समूह करता है ताकि यह देखा जा सके कि आप रडार के नीचे रहते हैं या नहीं।

$ ./al-khaser.exe -h
Usage: al-khaser.exe [OPTIONS]
Options:
--check <type> Enable specific check(s). Can be used multiple times. Valid types are:
TLS (Thread Local Storage callback checks)
DEBUG (Anti-debugging checks)
INJECTION (Code injection checks)
GEN_SANDBOX (Generic sandbox checks)
VBOX (VirtualBox detection)
VMWARE (VMware detection)
VPC (Virtual PC detection)
QEMU (QEMU detection)
KVM (KVM detection)
XEN (Xen detection)
WINE (Wine detection)
PARALLELS (Parallels detection)
HYPERV (Hyper-V detection)
CODE_INJECTIONS (Additional code injection techniques)
TIMING_ATTACKS (Timing/sleep-based sandbox evasion)
DUMPING_CHECK (Dumping memory/process checks)
ANALYSIS_TOOLS (Analysis tools detection)
ANTI_DISASSM (Anti-disassembly checks)
--sleep <seconds> Set sleep/delay duration in seconds (default: 600).
--delay <seconds> Alias for --sleep.
-h, --help Show this help message and exit.
Examples:
al-khaser.exe --check DEBUG --check TIMING_ATTACKS --sleep 30
al-khaser.exe --check VMWARE --check QEMU
al-khaser.exe --sleep 30
आप इस प्रोजेक्ट के रिलीज़ पेज से बिल्ट बाइनरीज़ (x86, x64) डाउनलोड कर सकते हैं। 7z का पासवर्ड यहाँ पाया जा सकता है।
कृपया, यदि आप कोई भी एंटी-विश्लेषण चाल देखते हैं जो आपने मैलवेयर में देखी है, तो योगदान करने में संकोच न करें।
sample.exe या sandbox.exe जैसे फ़ाइल नाम।रजिस्ट्री कुंजी मान कलाकृतियाँ
रजिस्ट्री कुंजी कलाकृतियाँ
फ़ाइल सिस्टम कलाकृतियाँ
पुल अनुरोधों का स्वागत है। कृपया यदि आप परियोजना में योगदान देना चाहते हैं तो हमारी विकी पर डेवलपर दिशानिर्देश पढ़ें।
निर्देशिका कलाकृतियाँ
मेमोरी कलाकृतियाँ
MAC पता
वर्चुअल डिवाइस
हार्डवेयर डिवाइस जानकारी
सिस्टम फर्मवेयर तालिकाएँ
ड्राइवर सेवाएँ
एडॉप्टर नाम
विंडोज़ क्लास
नेटवर्क शेयर
प्रक्रियाएँ
WMI
DLL निर्यात और लोड की गई DLLs
CPU
NtQueryLicenseValue को लाइसेंस मान के रूप में Kernel-VMDetection-Private के साथ।