Quantcast
Channel: Sysinternals Forums
Viewing all articles
Browse latest Browse all 10386

Malware : Malware analysis question

$
0
0
Author: blackhat401
Subject: Malware analysis question
Posted: 19 December 2014 at 5:28pm

Hello All,

I was trying to understand why the following function calls were categorized as Anti-Emulation/VM Detection. I am curious to know what information does it cough up to infer that the malware is running under a VM. I saw this on one of the automated reports.

GetVersionExW@KERNEL32.DLL
GetVersionExW@KERNEL32.DLL
GetVersionExA@KERNEL32.DLL

Many Thanks!

Viewing all articles
Browse latest Browse all 10386

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>