Although they did not disclose any specific details about how the so called detection actually works, we could inspect it a bit further. It simply scans through the resources of the currently running processes and looks for specific patterns for instance inside the “CompanyName” field, such like:vmwaresandboxvirtualboxgeswallbufferzonesafespaceNevertheless, the tricky part comes here. When a virtualized environment detected, unlike many other Trojans that stop to work, Citadel will continue to operate, but behaves in a different manner. It will generate a unique-machine dependent domain name obviously fake and tries to connect to this server unsuccessfully, making it to believe that the bot is dead and its command and control server is offline, meanwhile the real C&C domain is kept hidden.


via S21sec Security Blog: Citadel Updates: Anti-VM and Encryption change.

7 comments so far

Add Your Comment
  1. articoli da voi, l’uomo. Sono tenere conto la tua roba prima e sei semplicemente estremamente grande.
    I realmente Hai ottenuto qui, realmente sei dicendo e
    il modo migliore in cui dici esso. Stai facendo che divertente e
    si continua a cura di dormire è sensato . I non può imparare molto di più da voi.
    Questo è realtà a formidabile sito web.

  2. Excellent blog right here! Additionally your website a lot up very fast!
    What web host are you the usage of? Can I get your affiliate link on your host?
    I desire my web site loaded up as fast as yours lol

  3. Ciaο una mia amica mi ha girato l’indirizzo di qսesto
    sito e sono venuto a ѵedere se veramente merita. Mi piace parecchio.
    Messo trɑ i preferiti. Belllissimo blog e template spettacoloso!!

  4. Hello, i think that i saw you visited my site thus i got here to go back the favor?.I am trying to
    find issues to improve my site!I uess its ok to use a few
    of your ideas!!

  5. What i do not understood is in reality how you’re no longer actually much more neatly-favored
    than you might be right now. You’re very intelligent.
    You already know thus considerably in relation to this matter, made me in my view imagine it from a lot of numerous angles.
    Its like women and men aren’t involved except it’s something to
    accomplish with Girl gaga! Your personal stuffs outstanding.
    All the time deal with it up!

  6. Have you ever thought about including a little bit more than just your articles?

    I mean, what you say is fundamental and all. However think of if you added some great graphics or video
    clips to give your posts more, “pop”! Your content is excellent but with pics and videos,
    this site could definitely be one of the greatest in its niche.

    Terrific blog!

  7. Hurrah, that’s what I was seeking for, what a information! existing here at this web
    site, thanks admin of this web page.