EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsHard

A security researcher is analyzing a new variant of malware that is designed to steal banking credentials. The malware employs techniques to detect if it is running inside a virtual machine or a sandbox environment, and if so, it terminates its execution. Which malware evasion technique is this malware utilizing?

  1. AAnti-analysis
  2. BStealth
  3. CPolymorphism
  4. DObfuscation
Show answer & explanation

Correct answer: A. Anti-analysis

Anti-analysis techniques, specifically anti-virtual machine (anti-VM) and anti-sandbox detection, are designed to prevent security researchers from easily analyzing malware in controlled environments. By terminating execution when a VM or sandbox is detected, the malware evades analysis and hides its true malicious behavior.

Why the other options are wrong

  • B. Stealth is a broader term for hiding malware presence (e.g., rootkits), but anti-analysis specifically refers to detecting analysis tools/environments.
  • C. Polymorphism involves changing code/signatures to evade signature-based detection, not detecting analysis environments.
  • D. Obfuscation makes code difficult to understand, but doesn't necessarily involve detecting and reacting to a sandbox environment.

Anti-analysis Techniques

Methods used by malware to detect and evade analysis environments, such as virtual machines, sandboxes, debuggers, or security tools, to prevent researchers from understanding its full functionality.

  • Detects presence of VMs, sandboxes, debuggers.
  • Can alter behavior or terminate execution when detected.
  • Aims to frustrate and prolong malware analysis efforts.

Memory trick: Anti-analysis says 'No entry' to the security lab.

More Malware Threats questions