you are welcome
Best Regards,
Amr
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
I want my Azure Windows 10 sandbox to act more like a host not as a guest, while some of the malware are able to detect virtual environments.
To check how the sanbox might look like for a malware and then where to look for optimization I used a tool called Pafish created by Alberto Ortega and others.
https://github.com/a0rtega/pafish
"The goal of this project is to collect techniques commonly observed in malware samples to evade analysis systems. This allows analysts to study them and test whether the analysis environments are properly implemented"
While analyzing the output of the pafish file I saw that there are few possibilities for the malware to detect the virtual environment.
I'm interested in making the instance more like a host.
The output of the pafish binary looks like this:
[*] Checking the difference between CPU timestamp counters (rdtsc) forcing VM exit ... traced!
[*] Checking hypervisor bit in cpuid feature bits ... traced!
[*] Checking cpuid hypervisor vendor for known VM vendors ... traced!
[*] Checking mouse click activity ... traced!
[*] Checking mouse double click activity ... traced!
[*] Checking dialog confirmation ... traced!
[*] Checking plausible dialog confirmation ... traced!
[pafish] CPU VM traced by checking the difference between CPU timestamp counters (rdtsc) forcing VM exit
[pafish] CPU VM traced by checking hypervisor bit in cpuid feature bits
[pafish] CPU VM traced by checking cpuid hypervisor vendor for known VM vendors
[pafish] Sandbox traced by missing mouse click activity
[pafish] Sandbox traced by missing double click activity
[pafish] Sandbox traced by missing dialog confirmation
[pafish] Sandbox traced by missing or implausible dialog confirmation
[pafish] End
How can I optimize my Windows 10 sandbox instance based of the given information?
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
you are welcome
Best Regards,
Amr
Hello Amr.
Thanks for the tip.
Br GoralQ
Hello GoralQ,
I'm Amr, an independent advisor.
I apologize that this forum is for home users. Your query is more technical in nature, so could you please post this question on Microsoft Q&A
Microsoft Site Q&A forum is frequented by IT experts who can help you with your problem.
https://learn.microsoft.com/en-us/answers/quest...
Have a great day.
Best Regards,
Amr