项目简介
反沙箱检测
进程黑名单
"vmsrvc", "tcpview", "wireshark", "visual basic", "fiddler", "vmware", "vbox", "process explorer", "autoit", "vboxtray", "vmtools", "vmrawdsk", "vmusbmouse", "vmvss", "vmscsi", "vmxnet", "vmx_svga", "vmmemctl", "df5serv", "vboxservice", "vmhgfs", "vmtoolsd"
MAC地址检测
"000569","000C29","001C14","005056","080027"
磁盘检测
启动启动时间检测
CPU核心数量与语言检测
时间加速检测
bypass技术
-
进程镂空
-
Dinvoke 调用API
-
载入第二个NTDLL绕过HOOK
-
映射注入
-
syscall
项目结构

项目地址:https://github.com/MicrobBlue/BiFang