EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsHard
A security researcher is analyzing a new variant of malware that is designed to steal banking credentials. The malware employs techniques to detect if it is running inside a virtual machine or a sandbox environment, and if so, it terminates its execution. Which malware evasion technique is this malware utilizing?
- AAnti-analysis
- BStealth
- CPolymorphism
- DObfuscation
Show answer & explanationAnswer & explanation
Correct answer: A. Anti-analysis
Anti-analysis techniques, specifically anti-virtual machine (anti-VM) and anti-sandbox detection, are designed to prevent security researchers from easily analyzing malware in controlled environments. By terminating execution when a VM or sandbox is detected, the malware evades analysis and hides its true malicious behavior.
Why the other options are wrong
- B. Stealth is a broader term for hiding malware presence (e.g., rootkits), but anti-analysis specifically refers to detecting analysis tools/environments.
- C. Polymorphism involves changing code/signatures to evade signature-based detection, not detecting analysis environments.
- D. Obfuscation makes code difficult to understand, but doesn't necessarily involve detecting and reacting to a sandbox environment.
Anti-analysis Techniques
Methods used by malware to detect and evade analysis environments, such as virtual machines, sandboxes, debuggers, or security tools, to prevent researchers from understanding its full functionality.
- Detects presence of VMs, sandboxes, debuggers.
- Can alter behavior or terminate execution when detected.
- Aims to frustrate and prolong malware analysis efforts.
Memory trick: Anti-analysis says 'No entry' to the security lab.