typetechniqueconfidencehighcreated2026-07-26updated2026-07-26anti-analysisvm-detectionregistrydiskenumvboxvmwareqemu

Registry Disk Enum VM Detection

A sandbox/VM evasion technique that reads the Disk\Enum registry key to detect virtualised storage controllers.

Mechanism

  1. Open HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Disk\Enum via RegOpenKeyExA.
  2. Query the default value via RegQueryValueExA.
  3. Case-insensitive substring search for:
    • VBOX → Oracle VirtualBox
    • VMWARE → VMware Workstation/ESXi
    • QEMU → QEMU/KVM

Observed Implementations

  • Sample 60996777bf4f37e0eec2a99d450664278f103077f12a4b59178ff240ccb1b803 (unclassified-mingw64-https-stager) performs this check before initiating its HTTPS download. Failure (VM detected) causes early termination. ^[r2:fcn.1400121c0]

Detection / Fingerprint

  • API sequence: RegOpenKeyExA → RegQueryValueExA on path containing Services\Disk\Enum.
  • String artefacts: plaintext VBOX, VMWARE, QEMU in .rdata.

Defensive Countermeasures

  • Registry hooking / ETW: flag reads to Disk\Enum from non-system processes.
  • Hypervisor hardening: rename disk controller strings (e.g. VMware → custom) — breaks this specific check but not robust against other VM detection.