GIAC
GREM · Question #122
A malware sample checks the registry key: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId What is the MOST likely purpose?
The correct answer is B. Sandbox / VM detection. See the full explanation below for the reasoning.
Question
A malware sample checks the registry key:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId What is the MOST likely purpose?
Options
- APersistence creation
- BSandbox / VM detection
- CC2 configuration retrieval
- DDriver loading
How the community answered
(28 responses)- A7% (2)
- B79% (22)
- C4% (1)
- D11% (3)
Community Discussion
No community discussion yet for this question.