Skip to content

Scrut1ny/Hypervisor-Phantom

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 

Repository files navigation

🕵️ Advanced Malware Analysis Tool 🕵️

This tool provides an automated setup solution designed to evade detection from advanced malware, enabling thorough analysis. It employs a highly customized version of QEMU/KVM, EDK2, and the Linux Kernel. This also spoofs many unique hypervisor identifiers, effectively disguising the environment. This setup enhances the accuracy and reliability of malware analysis by minimizing the risk of detection.

pic

📖 Setup Instruction Guide

Expand for details...
# 1. Clone into the repository
git clone --single-branch --depth=1 https://github.com/Scrut1ny/Hypervisor-Phantom

# 2. CD into the repository
cd Hypervisor-Phantom/Hypervisor-Phantom/

# 3. Set executable permissions
chmod -R +x *

# 4. Run the script
./Auto-Hypervisor.sh

📝 Documentation & References

Expand for details...

💾 Software

HV Detection, Anti-Cheat and Exam Software

Hypervisor Detection Software

⭐ Rating 💻 Software 🧪 System Test ✅ Bypassed
🥇 VMAware Repository Link
⬇ Download - x64 - v2.4.1 ⬇
⬇ Download - x32 - v2.4.1 ⬇
⬇ Download - DEBUG - v2.4.1 ⬇
🥈 Al-Khaser (Obsolete) Repository Link
⬇ Download - x64 - v1.0.0 ⬇
⬇ Download - x32 - v1.0.0 ⬇
🥉 Pafish (Obsolete) Repository Link
⬇ Download - x64 - v0.6 ⬇
⬇ Download - x32 - v0.6 ⬇

Exam Software

💻 Software 🌐 Browser Extension 🧪 System Test ⬇️ Download ✅ Bypassed
Bluebook ⬇ Download ⬇
ExamSoft: Examplify ⬇ Download ⬇
Examity System Test ⬇ Firefox ⬇
⬇ Chrome ⬇
Honorlock Honorlock
⬇ Chrome ⬇
Inspera Exam Portal Demo Exam Instructions ⬇ Download ⬇
Kryterion System Test ⬇ Download ⬇
Pearson VUE System Test
System Test
ProctorU ⬇ Firefox ⬇
⬇ Chrome ⬇
ProctorU: Guardian Browser System Test ⬇ Download ⬇
Meazure Learning Page
ProctorU Page
Proctorio System Test
Respondus (LockDown Browser) System Test ⬇ Download ⬇
Safe Exam Browser System Test ⬇ Download ⬇

Anti-Cheat Software

🛡️ Engine 🎮 Used By ✅ Bypassed
Anti-Cheat Expert (ACE) Primarily Mobile Games
BattlEye (BE) Desktop Games ✅ (w/Windows Hyper-V + HVCI)
Easy Anti-Cheat (EAC) Desktop Games
Gepard Shield PUBG: Battlegrounds
NACE (Netease Anticheat Expert) Marvel Rivals
Hyperion Roblox
Mhyprot Genshin Impact ❔ (HoYoKProtect.sys)
🪟 BSOD: ATTEMPTED_WRITE_TO_READONLY_MEMORY
nProtect GameGuard (NP) Desktop Games
RICOCHET CoD Games
Vanguard Valorant & LoL ✅ (w/Windows Hyper-V + HVCI)
Virtual Video & Audio

Bring live video from your smartphone, remote computer, or friends directly into OBS or other studio software.

VB-CABLE Virtual Audio Device

Virtual Display Driver

Webcam Manipulation

VPN + Hypervisor
  • IMPORTANT: Ensure not to add a custom DNS configuration to the guest system on the hypervisor if your host system's VPN uses custom DNS block lists. Doing so may result in your guest hypervisor system losing its internet connection!

Mullvad VPN + QEMU

  • For the VPN connection to get properly natted/bridged you must enable the setting Local network sharing option!
    • How to: ⚙️ > VPN settings > Local network sharing

image image image image

Recommended Tools

🔩 Hardware

Bypassing HDCP

HDCP (High-bandwidth Digital Content Protection) Stuff

Bypassing HDCP Hardware/Software Diagram:

bypass

Bypass Kits

Expensive Bypass Kit (Recommended):

Cheap Bypass Kit (Not recommended):

  • 1x2 HDMI Splitter <> OREI - ~$13.00
  • EDID Emulator <> EVanlak - ~$7.00
  • USB HDMI Capture Card <> AXHDCAP - ~$9.00

Equipment List

Elgato Capture Cards
  • Some of Elgato's capture cards, leveraging UVC (USB Video Class) technology, operate seamlessly without requiring additional drivers. As UVC devices, they adhere to a standard protocol for transmitting video and audio data over USB connections. This plug-and-play functionality ensures compatibility with various operating systems, enabling effortless setup and use for capturing high-quality video content.

UVC Elgato Capture Cards

Device Driver Status
Elgato Cam Link No driver since it's a UVC device
Elgato Cam Link 4K No driver since it's a UVC device
Elgato Game Capture HD60 S+ No driver since it's a UVC device
Elgato Game Capture HD60 X No driver since it's a UVC device
Game Capture 4K X No driver since it's a UVC device
Game Capture Neo No driver since it's a UVC device

Linux - OBS Black Screen Issue Solution

Step 1:

Download and Install the latest 4K CAPTURE UTILITY software from Elgato downloads page on a WINDOWS OS.

Step 2:

Open Elgato 4K Capture Utility and let the software initialize the UVC capture card.

Step 3:

Select the settings icon on the top right corner of the software utility, and select Check for Updates.... (It should update automatically already, but just make sure the firmware is on the latest version available.)

Step 4:

Now, connect the capture card device back to your Linux host system now and open OBS, you should now see an output from your GPU instead of a black screen.


⚠️ Legal Disclaimer
By using this tool, you agree to the following:

  • This tool is intended only for educational, research, and security analysis purposes.
  • The author is not liable for any damages, legal consequences, or misuse arising from your use of this tool.
  • You are responsible for ensuring your use complies with all applicable laws.
  • Misuse, including cheating or illegal activities, is strictly prohibited.

Use at your own risk. The tool is provided "as-is" without any warranties.


Star History

Star History Chart