AVLeak: Fingerprinting Antivirus Emulators for Advanced Malware Evasion

  Рет қаралды 2,883

Black Hat

Black Hat

Күн бұрын

by Alexei Bulazel
AVLeak is a tool for fingerprinting consumer antivirus emulators through automated black box testing. AVLeak can be used to extract fingerprints from AV emulators that may be used by malware to detect that it is being analyzed and subsequently evade detection, including environmental artifacts, OS API behavioral inconsistencies, emulation of network connectivity, timing inconsistencies, process introspection, and CPU emulator "red pills."
Emulator fingerprints may be discovered through painstaking binary reverse engineering, or with time consuming black box testing using binaries that conditionally choose to behave benignly or drop malware based on the emulated environment. AVLeak significantly advances upon prior approaches to black box testing, allowing researchers to extract emulator fingerprints in just a few seconds, and to script out testing using powerful APIs.
AVLeak will be demoed live, showing real world fingerprints discovered using the tool that can be used to detect and evade popular consumer AVs including Kaspersky, Bitdefender engine (licensed out to 20+ other AV products), AVG, and VBA. This survey of emulation detection methods is the most comprehensive examination of the topic ever presented in one place.

Пікірлер: 5
@StavBenHorin
@StavBenHorin 6 жыл бұрын
Its not just u, he even drinks water with the same annoyed approach..
@borisb1831
@borisb1831 7 жыл бұрын
Damn I dont know why but the way he speaks is just pissing me off, its so disgusting. Maybe I need more sleep
@disk0__
@disk0__ 7 жыл бұрын
Boris Bagryanskiy mic is not the best, it's picking up every minute grazing on his shirt as well as every bit of air he's breathing
Brute-Forcing Lockdown Harddrive Pin Codes
25:38
Black Hat
Рет қаралды 3,1 М.
You Shall Not PASS - Analysing a NSO iOS Spyware Sample
40:22
Black Hat
Рет қаралды 3,3 М.
Officer Rabbit is so bad. He made Luffy deaf. #funny #supersiblings #comedy
00:18
Funny superhero siblings
Рет қаралды 14 МЛН
Good teacher wows kids with practical examples #shorts
00:32
I migliori trucchetti di Fabiosa
Рет қаралды 4 МЛН
Running a Buffer Overflow Attack - Computerphile
17:30
Computerphile
Рет қаралды 2 МЛН
John Oliver Is Still Working Through the Rage
37:32
New York Times Podcasts
Рет қаралды 1,7 МЛН
When you Accidentally Compromise every CPU on Earth
15:59
Daniel Boctor
Рет қаралды 833 М.
GHIDRA for Reverse Engineering (PicoCTF 2022 #42 'bbbloat')
17:44
John Hammond
Рет қаралды 211 М.
How A Steam Bug Deleted Someone’s Entire PC
11:49
Kevin Fang
Рет қаралды 1 МЛН
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН
Officer Rabbit is so bad. He made Luffy deaf. #funny #supersiblings #comedy
00:18
Funny superhero siblings
Рет қаралды 14 МЛН