{"id":8047,"date":"2022-04-16T21:19:42","date_gmt":"2022-04-16T21:19:42","guid":{"rendered":"https:\/\/www.hexacorn.com\/blog\/?p=8047"},"modified":"2022-04-16T22:00:57","modified_gmt":"2022-04-16T22:00:57","slug":"the-anti-vm-trick-that-is-kinda-personal","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2022\/04\/16\/the-anti-vm-trick-that-is-kinda-personal\/","title":{"rendered":"The Anti-VM trick that is kinda&#8230; personal"},"content":{"rendered":"\n<p>I have written a lot about anti-vm tricks, and while this topic is so worn out that almost feels like kicking a dead horse I felt there is still a scope for some &#8216;novelty&#8217; approach&#8230;<\/p>\n\n\n\n<p>As a hobby, I started jotting down OPSEC failures from random reverse engineers and security professionals. I didn&#8217;t go too far, but once you see the list, you will get the gist and can easily expand on it a bit more. <\/p>\n\n\n\n<p>Trust me, this is nothing personal. But yeah, it totally is \ud83d\ude42<\/p>\n\n\n\n<p>Analysing screenshots shared on social media I was able to jot down some notes on the user names used by the researchers&#8217; boxes\/test environments. Some of these user names are generic, and as such, not very helpful, but hey&#8230; many actually are pretty specific!<\/p>\n\n\n\n<p>So, a personalized anti-* trick could simply add these known user names to a &#8216;we don&#8217;t run here&#8217; list i.e. if any of these user names is found on the system &#8211;&gt; gracefully exit.<\/p>\n\n\n\n<p>Not very complex&#8230; but you didn&#8217;t see it coming!<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><tbody><tr><td><strong>Twitter Handle<\/strong><\/td><td><strong>User name<\/strong><\/td><\/tr><tr><td>pr0xylife<\/td><td>pr0xylifelab<\/td><\/tr><tr><td>mrd0x<\/td><td>mr.d0x<\/td><\/tr><tr><td>Wietze<\/td><td>Wietze<\/td><\/tr><tr><td>inversecos<\/td><td>Lina Lau<\/td><\/tr><tr><td>mohammadaskar2<\/td><td>askar<\/td><\/tr><tr><td>DissectMalware<\/td><td>aniak<\/td><\/tr><tr><td>falsneg<\/td><td>freddy<\/td><\/tr><tr><td>Oddvarmoe<\/td><td>oddva<\/td><\/tr><tr><td>mrAn61<\/td><td>taro<\/td><\/tr><tr><td>SBousseaden<\/td><td>bouss<\/td><\/tr><tr><td>vinopaljiri<\/td><td>Inferno<\/td><\/tr><tr><td>stvemillertime<\/td><td>steve<\/td><\/tr><tr><td>x86matthew<\/td><td>Win10<\/td><\/tr><tr><td>0gtweet<\/td><td>Administrator<\/td><\/tr><tr><td>0gtweet<\/td><td>Admin<\/td><\/tr><tr><td>jonasLyk<\/td><td>jonas<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Honorary <a href=\"https:\/\/twitter.com\/Ledtech3\/status\/1515441727632551937\">mention<\/a>:<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><tbody><tr><td><strong>Twitter Handle<\/strong><\/td><td><strong>User name<\/strong><\/td><\/tr><tr><td>Ledtech3<\/td><td>JoeUser<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Update<\/strong><\/p>\n\n\n\n<p>Not all these are correct findings f.ex. see <a href=\"https:\/\/twitter.com\/pr0xylife\/status\/1515449282576400387\">response<\/a> from <a href=\"https:\/\/twitter.com\/pr0xylife\">proxylife<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>I have written a lot about anti-vm tricks, and while this topic is so worn out that almost feels like kicking a dead horse I felt there is still a scope for some &#8216;novelty&#8217; approach&#8230; As a hobby, I started &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2022\/04\/16\/the-anti-vm-trick-that-is-kinda-personal\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[43],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8047"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=8047"}],"version-history":[{"count":5,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8047\/revisions"}],"predecessor-version":[{"id":8055,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/8047\/revisions\/8055"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=8047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=8047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=8047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}