Skip to Content
Evasive Malware
book

Evasive Malware

by Kyle Cucci
September 2024
Intermediate to advanced
488 pages
13h 29m
English
No Starch Press
Content preview from Evasive Malware

7 RUNTIME ENVIRONMENT AND VIRTUAL PROCESSOR ANOMALIES

In the previous three chapters, you’ve seen how malware can query and enumerate OS artifacts and configurations to understand its environment and detect that it’s being analyzed. This chapter will focus on how malware can actively identify analysis sandboxes and VM environments by inspecting the anomalies that malware analysis tools introduce, monitoring virtual processor performance and timing, and abusing virtual processor instructions.

Detecting Analysis and Runtime Anomalies

When malware is executed in a sandbox or malware analysis environment, the sandbox or analysis tools can give ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Practical Malware Analysis

Practical Malware Analysis

Michael Sikorski, Andrew Honig
Security in Computing, 6th Edition

Security in Computing, 6th Edition

Charles Pfleeger, Shari Lawrence Pfleeger, Lizzie Coles-Kemp
Metasploit, 2nd Edition

Metasploit, 2nd Edition

David Kennedy, Mati Aharoni, Devon Kearns, Jim O'Gorman

Publisher Resources

ISBN: 9781098182236Errata Page