nerdexam
GIAC

GREM · Question #122

A malware sample checks the registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId What is the MOST likely purpose?

The correct answer is B. Sandbox / VM detection. See the full explanation below for the reasoning.

Question

A malware sample checks the registry key:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId What is the MOST likely purpose?

Options

  • APersistence creation
  • BSandbox / VM detection
  • CC2 configuration retrieval
  • DDriver loading

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    79% (22)
  • C
    4% (1)
  • D
    11% (3)

Community Discussion

No community discussion yet for this question.

Full GREM Practice