Using CPUID for detecting VMs
by Loki - Monday July 8, 2024 at 09:57 AM
#1
Hidden Content
You must register or login to view this content.


On a virtual machine, this returns a hypervisor-specific string across EBX, ECX, and EDX, such as "VMwareVMware," "Microsoft Hv," "VBoxVBoxVBox," or "XenVMMXenVMM.
[Image: e47c91a87cc521d1efbd20183b42ee4259c9c593.gifv]
PGP
Reply
#2
I'll check this against the hiddenvm I posted.
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | https://breachforums.hn/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#3
hello than you for that
Reply
#4
This is a neat little trick, but can also be easily thwarted by modifying the VM configuration file to set the CPUID to be whatever you want, such as a legit machine's CPUID. This shouldn't be used by itself, but along with several other anti-vm/anti-detect methods.
Reply
#5
(07-31-2024, 07:39 PM)notagh0st Wrote: This is a neat little trick, but can also be easily thwarted by modifying the VM configuration file to set the CPUID to be whatever you want, such as a legit machine's CPUID. This shouldn't be used by itself, but along with several other anti-vm/anti-detect methods.

certainly, this is just one of the tricks
[Image: e47c91a87cc521d1efbd20183b42ee4259c9c593.gifv]
PGP
Reply
#6
other than the cpuid if i remember correctly there are environment variables that are set by default by the hypervisor
Reply
#7
Making a custom protector so thanks
Reply
#8
(08-13-2024, 03:34 AM)Nukemaster1113 Wrote: Making a custom protector so thanks

that sounds like a cool project!
[Image: e47c91a87cc521d1efbd20183b42ee4259c9c593.gifv]
PGP
Reply
#9
learning more on vm shit so this is helpful thanks
Reply
#10
(08-13-2024, 04:05 AM)Loki Wrote:
(08-13-2024, 03:34 AM)Nukemaster1113 Wrote: Making a custom protector so thanks

that sounds like a cool project!

It’s really fun man just takes a ton of time because I’m trying to one up vmp
Reply


Forum Jump:


 Users browsing this thread: