Is the latest ransomware able to bypass VirtualBox?

Kalashnikov

Level 2
Thread author
Verified
Apr 13, 2016
52
As above , of course , co- resource SWITCHED OFF.I would like a little fun in the virtual machine , but I have concerns about the latest ransomware ... I do not want to lose data.Bearing in mind the latest , I have the most advanced and fresh...(Tesla,Petya,Locky etc..):rolleyes:.
 
L

LabZero

I have tested and analyzed dozens of ransomware in VirtualBox, and none of them has infected my host.
The important thing is not to activate the shared folders.
Everything is possible, but objectively I do not have experience of evasions.
 
D

Deleted member 178

I have tested and analyzed dozens of ransomware in VirtualBox, and none of them has infected my host.
The important thing is not to activate the shared folders.

Shared Folders can be activated but it must be protected then by other tools. (sandbox, anti-exe, folder lockers, etc...)

what about ransomware locking the MBR sector ? :).

It will encrypt the guest's MBR not the Host one.

.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Virtualbox contains so far the full proof of strong virtualization, which is not easy to bypass. (The chances of another new vulnerability is possible)

As you can see, the settings [Virtualbox] are all disabled per default so make sure that shared folder must monitored regularly to avoid any incidents.
 
L

LabZero

Update

During my last tests, some generic malware have recognized Vitualbox checking for the presence of the guest additions drivers.

Malware "could" escape the environment of the virtual machine: in the case of a host only network, any bugs present in the host network driver or in the host sevices that can be exploited through the sending of packages specially created, or exploiting bugs (for example, unchecked inputs).

It is always necessary to use the latest version of any VM (VBox and VMWare).
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top