3. Тестирование.
Тестирование проводим в соответствии со следующим видео от
Vektor T13 -
Presentation of free antidetect by Vektor T13 (English):
1. AntiVM Detection
1) al-khaser v0.77
Clone1:
[Thu Mar 7 04:09:01 2019] [*] Checking If Parent Process is explorer.exe -> 1
[Thu Mar 7 04:09:02 2019] [*] Checking Local Descriptor Table location -> 1
[Thu Mar 7 04:09:03 2019] [*] Checking hard disk size using WMI -> 1
[Thu Mar 7 04:10:09 2019] [*] Checking ProcessId using WMI -> 1
[Thu Mar 7 04:10:09 2019] [*] Checking power capabilities -> 1
[Thu Mar 7 04:10:10 2019] [*] Checking CPU fan using WMI -> 1
[Thu Mar 7 05:30:20 2019] [*] Checking RDTSC which force a VM Exit (cpuid) -> 1
Clone2:
[Thu Mar 7 16:13:20 2019] [*] Checking If Parent Process is explorer.exe -> 1
[Thu Mar 7 16:13:22 2019] [*] Checking Local Descriptor Table location -> 1
[Thu Mar 7 16:13:24 2019] [*] Checking hard disk size using WMI -> 1
[Thu Mar 7 16:13:29 2019] [*] Checking mouse movement -> 1
[Thu Mar 7 16:14:30 2019] [*] Checking ProcessId using WMI -> 1
[Thu Mar 7 16:14:30 2019] [*] Checking power capabilities -> 1
[Thu Mar 7 16:14:30 2019] [*] Checking CPU fan using WMI -> 1
[Thu Mar 7 17:34:41 2019] [*] Checking RDTSC which force a VM Exit (cpuid) -> 1
2) pafish v058
Clone1: [pafish] CPU VM traced by checking the difference between CPU timestamp counters (rdtsc) forcing VM exit
Clone2: [pafish] CPU VM traced by checking the difference between CPU timestamp counters (rdtsc) forcing VM exit
3) VMDE v1.1.0
Clone1: Noting Detected
Clone2: Noting Detected
4) ScoopyNG
Clone1: Native OS on Tests 1-7
Clone2: Native OS on Tests 1-7
5) Machine ID
Clone1: Detect Virtual Machine - disable
Clone2: Detect Virtual Machine - disable
6) Filename Search
Clone1:
"virtualbox" - None
"vbox" - "C:\Program Files\Vektor T13\Antidetect Guest Additions\VBoxDrvInst.exe"
Clone2:
"virtualbox" - None
"vbox" - "C:\Program Files\Vektor T13\Antidetect Guest Additions\VBoxDrvInst.exe"
7) Regedit Search
Clone1:
"vbox"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\Drives\Volume{1822d7c7-40ac-11e9-873f-806e6f6e6963}\Current Media]
...
"Disc Label"="
VBOXADDITIONS_5."
[HKEY_USERS\S-1-5-21-1634589048-718573563-2350836972-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\Drives\Volume{1822d7c7-40ac-11e9-873f-806e6f6e6963}\Current Media]
...
"Disc Label"="
VBOXADDITIONS_5."
"virtualbox"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DriverUpdater]
...
"DisplayName"="
VirtualBox Guest Additions Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LogitechMouse2Q]
...
"DisplayName"="
VirtualBox Guest Mouse Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\DriverUpdater]
...
"DisplayName"="
VirtualBox Guest Additions Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\LogitechMouse2Q]
...
"DisplayName"="
VirtualBox Guest Mouse Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DriverUpdater]
...
"DisplayName"="
VirtualBox Guest Additions Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\LogitechMouse2Q]
...
"DisplayName"="
VirtualBox Guest Mouse Service"
Clone2:
"vbox"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\Drives\Volume{4335fd27-4133-11e9-a184-806e6f6e6963}\Current Media]
...
"Disc Label"="
VBOXADDITIONS_5."
[HKEY_USERS\S-1-5-21-2672700163-1186345451-1578211240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CD Burning\Drives\Volume{4335fd27-4133-11e9-a184-806e6f6e6963}\Current Media]
...
"Disc Label"="
VBOXADDITIONS_5."
"virtualbox"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DriverUpdater]
...
"DisplayName"="
VirtualBox Guest Additions Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LogitechMouse2Q]
...
"DisplayName"="
VirtualBox Guest Mouse Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\DriverUpdater]
...
"DisplayName"="
VirtualBox Guest Additions Service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\services\LogitechMouse2Q]
...
"DisplayName"="
VirtualBox Guest Mouse Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DriverUpdater]
...
"DisplayName"="
VirtualBox Guest Additions Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\LogitechMouse2Q]
...
"DisplayName"="
VirtualBox Guest Mouse Service"
2. Hardware Randomization System
1) Machine ID
Clone1:
HDD: 9660-6684-71C5-31D4
BIOS: DC81-3B0E-B281-539F
CPU: EF87-E424-DCD8-247C
Clone2:
HDD: FD7A-DED1-4DFD-CF3B
BIOS: FD29-3DEE-CC19-6F58
CPU: 4555-CD60-C985-5F96
2) PCI-Z
Clone1:
Clone2:
3) Audio Equipment
Clone1:
Hardware ID: HDAUDIO\FUNC_01&VEN_10C8&DEV_8016&SUBSYS_10C87680&REV_1034
Speakers Properties: 20 bit, 16000 Hz
Clone2:
Hardware ID: HDAUDIO\FUNC_01&VEN_109E&DEV_0878&SUBSYS_109E7680&REV_1034
Speakers Properties: 16 bit, 88200 Hz
4) Monitor Emulation
Clone1: Dell 1701FP
Clone2: Compaq TFT8000 Flat Panel Monitor
5) MAC Vendor
Clone1:
Physical Address: 70-79-38-D0-2B-08
Transport Name: \Device\Tcpip_{2ADB5D91-B083-47AB-8163-D5893858AC4F}
Clone2:
Physical Address: 20-76-93-B0-0B-5C
Transport Name: \Device\Tcpip_{3F1AA8FE-93F4-44C2-A53E-6C685994260E}
3. Antidetect Guest Additions
1) System Properties
Clone1: Computers Performance: Windows Experience Index could not be computed error
Clone2: Computers Performance: Windows Experience Index = 5.9
2) Screen Resize / Clipboard test
Clone1:
Screen Resizes:
640x480 ->
1024x768
800x600 ->
1024x768
1024x768 ->
Yes
1152x864 ->
Yes
0x960 ->
Yes
0x1024 ->
Yes
1360x768 ->
Yes
1366x768 ->
1360x768
1400x1050 ->
Yes
1600x900 ->
Yes
1600x1024 ->
Yes
1600x1200 ->
None
1680x1050 ->
Yes
1920x975 ->
None
1920x1080 -> None
1920x1200 -> None
Clipboard test: Yes
Clone2:
Screen Resizes:
640x480 ->
Yes
800x600 ->
Yes
1024x768 ->
Yes
1152x864 ->
Yes
0x960 ->
Yes
0x1024 ->
Yes
1360x768 ->
Yes
1366x768 ->
Yes
1400x1050 ->
Yes
1600x900 ->
Yes
1600x1024 ->
Yes
1600x1200 ->
None
1680x1050 ->
Yes
1920x975 -> None
1920x1080 -> None
1920x1200 -> None
Clipboard test: Yes
4. Browser Fingerprints
1) WebRTC local IP and I/O devices IDs
Clone1:
Checked via
BrowserLeaks.com in Firefox
IP Address Detection
Local IP Address: 172.25.17.15
Public IP Address: 9x.xxx.xxx.xx3
Media Devices
kind: audioinput
deviceId: vCGgJDRG3FD493vvKLw3wpP1UtaJSxagq8hD57HQh5Y=
label: n/a
Clone2:
Checked via
BrowserLeaks.com in Firefox
IP Address Detection
Local IP Address: 172.29.8.15
Public IP Address: 9x.xxx.xxx.xx3
Media Devices
kind: audioinput
deviceId: fTM/pe1kYjjTcJpBkp61k4u789BcjTPHg4GvhBN1GmQ=
label: n/a
2) Canvas fingerprint
Clone1:
Checked via
BrowserLeaks.com in Chrome/Firefox
Your Fingerprint
Signature: 1D7AA0FC / B305455D
Uniqueness: 99.97% (142 of 411582 user agents have the same signature) / 99.94% (244 of 411582 user agents have the same signature)
Checking Hardware Acceleration via Google Chrome:
chrome://gpu/
Canvas: Software only, hardware acceleration unavailable
Clone2:
Checked via
BrowserLeaks.com in Chrome/Firefox
Your Fingerprint
Signature: 1D7AA0FC / B305455D
Uniqueness: 99.97% (142 of 411582 user agents have the same signature) / 99.94% (244 of 411582 user agents have the same signature)
Checking Hardware Acceleration via Google Chrome:
chrome://gpu/
Canvas: Hardware accelerated
3) WebGL fingerprint
Clone1:
Checked via
BrowserLeaks.com in Chrome/Firefox
WebGL1 -
True/True
WebGL2 -
True/True
WebGL Report Hash:
9A8941DF1FD864E53BD10DE58E41116E / 7f75e5bcfc0f1d29e236d3d89ff98dbe
WebGL Image Hash:
15C2CD008A6BFD6DD3D02FD2B7EB3F14 / 42f3ecf80b0132497576dc52941323d9
Checked via
WebGL Report in Chrome/Firefox
WebGL1 -
Yes/Yes
WebGL2 -
Yes/Yes
Clone2:
Checked via
BrowserLeaks.com in Chrome/Firefox
WebGL1 -
True/True
WebGL2 -
False/False
WebGL Report Hash:
AD039BE1705F65B55CBED000BFF353A9 / 93c2bb556e6f51c978553ca59b525cd9
WebGL Image Hash:
E2F046261D904AC87AB73210384BA60F / e2f046261d904ac87ab73210384ba60f
Checked via
WebGL Report in Chrome/Firefox
WebGL1 -
Yes/Yes
WebGL2 -
None/None
None -
This browser supports WebGL 2, but it is disabled or unavailable.
4) Audio fingerprint
Checked via
AudioContext Fingerprint Test Page in Firefox
Clone1:
Fingerprint using DynamicsCompressor (sum of buffer values): 35.7383295930922
Fingerprint using DynamicsCompressor (hash of full buffer): 2dc43feaa1474319db71be0f4a9810c4a2a54524
Fingerprint using OscillatorNode: -120.82844543457031,-121.40194702148438,-120.58355790625
Fingerprint using hybrid of OscillatorNode/DynamicsCompressor method: -126.45063781738281,-118.34962463378906,-104.18365478515625
Clone2:
Fingerprint using DynamicsCompressor (sum of buffer values): 35.7383295930922
Fingerprint using DynamicsCompressor (hash of full buffer): 2dc43feaa1474319db71be0f4a9810c4a2a54524
Fingerprint using OscillatorNode: -106.62174224853516,-105.99589538574219,-104.47167205810547
Fingerprint using hybrid of OscillatorNode/DynamicsCompressor method: -115.48180389404297,-111.4937744140625,-114.75468444824219
5) Ubercookie fingerprint
Checked via
Ubercookie fingerprint in Firefox
Clone1 Fingerprint: afc254a612cdf7222bda4e5674b7a9671923a8c6
Clone2 Fingerprint: 31800a3e1c864202c8ad3d6e20ab4118c145410d