    How Malware Uses Screen Resolution to Avoid Detection

    There’s a lot more markers than just screen resolution that give away a virtualised environment though?

    So set my screen resolution to one of those and it’s basically free anti virus?

    This has been going on for years. Also, you can use screen resolution in the same way to verify you are on the target osdevice you want.

    Can anyone ELI5? 🙂

    So i could just switch my resolution when i open a download, wait for it to self detonate and then switch back?

    Windows Sandbox uses your native resolution, I also don’t know how virtualized it is. I think windows sandbox is just a sectioned off area. I always use it to test files.

    Just use Qubes guys

    >As a result, researchers sometimes don’t install the VM’s guest software. This software enables additional features such as higher screen resolutions, which the researcher doesn’t really need. If the user doesn’t use the guest software, the VM typically locks the user into one of two low resolutions: 800×600 and 1024×768.

    Who, in 2020, is running VMs at 800×600?

    This is very useful. Thank you for the info.

    I guess we should have developed separate Virtual Machine software focused on malware testing scenarios.

    That was interesting. You have to wonder how many other obvious markers there are that suggest you’re on a virtual machine rather than a real one.

    In fact maybe researchers should create a program whose sole purpose is to try to determine whether or not it;s running on a VM. They would learn from this.

    Man this is dangerous. Thanks for the info man

    MFW i’m protected against malware cause i use 1024 for some reasons lmao.

    Yeah, tor browser even advices you to have a minimum in the browser window. Nice evasion to use

    Can you run stuff like Kali Linux/Tor from a USB stick?

    Imagine, if you will, a Tor browser where every other user is a bot except YOU. Now imagine this Tor is available on the App Store and gets 5 stars. All the cool kids are using it.

