
Публичные методы вредоносного ПО, используемые в реальных условиях: обнаружение виртуальных машин, эмуляции, отладчиков и песочниц.

al-khaser — это PoC-приложение «вредоносное ПО» с благими намерениями, которое призвано нагрузить вашу антивирусную систему. Оно выполняет множество распространённых вредоносных трюков, чтобы проверить, останетесь ли вы незамеченным.

$ ./al-khaser.exe -h
Usage: al-khaser.exe [OPTIONS]
Options:
--check <type> Enable specific check(s). Can be used multiple times. Valid types are:
TLS (Thread Local Storage callback checks)
DEBUG (Anti-debugging checks)
INJECTION (Code injection checks)
GEN_SANDBOX (Generic sandbox checks)
VBOX (VirtualBox detection)
VMWARE (VMware detection)
VPC (Virtual PC detection)
QEMU (QEMU detection)
KVM (KVM detection)
XEN (Xen detection)
WINE (Wine detection)
PARALLELS (Parallels detection)
HYPERV (Hyper-V detection)
CODE_INJECTIONS (Additional code injection techniques)
TIMING_ATTACKS (Timing/sleep-based sandbox evasion)
DUMPING_CHECK (Dumping memory/process checks)
ANALYSIS_TOOLS (Analysis tools detection)
ANTI_DISASSM (Anti-disassembly checks)
--sleep <seconds> Set sleep/delay duration in seconds (default: 600).
--delay <seconds> Alias for --sleep.
-h, --help Show this help message and exit.
Examples:
al-khaser.exe --check DEBUG --check TIMING_ATTACKS --sleep 30
al-khaser.exe --check VMWARE --check QEMU
al-khaser.exe --sleep 30
Готовые бинарные файлы (x86, x64) можно скачать на странице релизов этого проекта. Пароль для 7z-архивов можно найти здесь.
Пожалуйста, если вы столкнётесь с какими-либо анти-аналитическими трюками, которые вы видели в вредоносном ПО, не стесняйтесь внести свой вклад.
sample.exe or sandbox.exe.Registry key value artifacts
Registry Keys artifacts
File system artifacts
Принимаются pull request'ы. Пожалуйста, ознакомьтесь с Руководством для разработчиков на нашей вики, если хотите внести вклад в проект.
Directories artifacts
Memory artifacts
MAC Address
Virtual devices
Hardware Device information
System Firmware Tables
Driver Services
Adapter name
Windows Class
Network shares
Processes
WMI
DLL Exports and Loaded DLLs
CPU
NtQueryLicenseValue with Kernel-VMDetection-Private as license value.