Skip to content

Commit e3930b0

Browse files
authored
Merge pull request #5 from EvilBytecode/main
Update (TRIAGE DETECTION)
2 parents 1d3fbb2 + c8c2ad1 commit e3930b0

File tree

2 files changed

+17
-0
lines changed

2 files changed

+17
-0
lines changed

AntiCrack-DotNet/AntiVirtualization.cs

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -282,6 +282,22 @@ public static bool CheckForParallels()
282282
return false;
283283
}
284284

285+
public static bool TriageCheck()
286+
{
287+
using (var searcher = new ManagementObjectSearcher("SELECT * FROM Win32_DiskDrive"))
288+
{
289+
foreach (var item in searcher.Get())
290+
{
291+
string model = item["Model"].ToString();
292+
if (model.Contains("DADY HARDDISK") || model.Contains("QEMU HARDDISK"))
293+
{
294+
return true;
295+
}
296+
}
297+
}
298+
return false;
299+
}
300+
285301
public static bool CheckForQemu()
286302
{
287303
string[] BadDriversList = { "qemu-ga", "qemuwmi" };

AntiCrack-DotNet/Program.cs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,7 @@ private static void ExecuteAntiDebuggingTricks()
104104
private static void ExecuteAntiVirtualizationTricks()
105105
{
106106
ConsoleConfig.DisplayHeader("Executing Anti Virtualization Tricks");
107+
ConsoleConfig.DisplayResult("Checking For Triage: ", AntiVirtualization.TriageCheck(), "Checks if Triage is present through disk.");
107108
ConsoleConfig.DisplayResult("Checking For Sandboxie Module in Current Process: ", AntiVirtualization.IsSandboxiePresent(), "Checks if Sandboxie is present.");
108109
ConsoleConfig.DisplayResult("Checking For Comodo Sandbox Module in Current Process: ", AntiVirtualization.IsComodoSandboxPresent(), "Checks if Comodo Sandbox is present.");
109110
ConsoleConfig.DisplayResult("Checking For Cuckoo Sandbox Module in Current Process: ", AntiVirtualization.IsCuckooSandboxPresent(), "Checks if Cuckoo Sandbox is present.");

0 commit comments

Comments
 (0)