Registry Disk Enum VM Detection
A sandbox/VM evasion technique that reads the Disk\Enum registry key to detect virtualised storage controllers.
Mechanism
- Open
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Disk\EnumviaRegOpenKeyExA. - Query the default value via
RegQueryValueExA. - Case-insensitive substring search for:
VBOX→ Oracle VirtualBoxVMWARE→ VMware Workstation/ESXiQEMU→ QEMU/KVM
Observed Implementations
- Sample
60996777bf4f37e0eec2a99d450664278f103077f12a4b59178ff240ccb1b803(unclassified-mingw64-https-stager) performs this check before initiating its HTTPS download. Failure (VM detected) causes early termination. ^[r2:fcn.1400121c0]
Detection / Fingerprint
- API sequence:
RegOpenKeyExA→RegQueryValueExAon path containingServices\Disk\Enum. - String artefacts: plaintext
VBOX,VMWARE,QEMUin.rdata.
Defensive Countermeasures
- Registry hooking / ETW: flag reads to
Disk\Enumfrom non-system processes. - Hypervisor hardening: rename disk controller strings (e.g. VMware → custom) — breaks this specific check but not robust against other VM detection.