Carding from virtual machine
Any programs running in this environment can be installed on a virtual machine, including
- Proxy socks5 services. Please note that the proxy must have been installed in the browser or used by special tunneling software for surfing the Internet.
- Antidetect browsers. Please note that the installation of a virtual machine does not make sense and does not matter much if you install the antidetect browser directly on the main system.
Using a bundle virtual machine + antidetect browser is not a reasonable solution for successful work, but it can provide an additional level of anonymity and security when working, so antidetect is an alternative to a virus machine and completely replaces its functionality and the need to use
- Programs for changing the MAC address
- Programs for cleaning the system registry and cookies
- Programs for changing the identifiers of the installed system equipment to new and unique
- VPN provider. But also vpn can work on top of a virtual system or installed with a separate browser plugin
- Programs for traffic encryption
- Access to the RDP or SSH tunnels is provided
Cleaning the system and changing all parameters is mandatory after the card has been fully worked out or you have received an account lock (ban) to bypass the anti-fraud system of the site you are working on.
If the card remains alive, then changing the parameters and identifiers to others is not required and is not a big necessity.
VMware: Bypassing the scan for a virtual machine
Some programs, such as online games and specialized software, refuse to run in a virtual machine. As I understand it, the program checks some signs of a virtual machine (vendor names, VID / PID of equipment, etc.) and when it finds a match it writes something like
"Sorry, this application cannot run under a virtual machine". Below is a small manual on bypassing a virtual machine detection for VMware Workstation. I can not guarantee that it is 100% working, because the options for determining the virtual machine are a wagon and a small cart, but it bypasses the most common checks.
To bypass the detection of a virtual machine, we need:
- VMware Workstation v 12.1.0 build 3272444
- Patched file vmware-vmx.exe with changed vendors. BIOS image from which the lines with "VMware" were removed and the serial number of the motherboard was added. You can download it from here.
- Straight arms.
1. Install VMware Workstation. The hosting rules forbid publishing broken software, you can go to the largest Russian-language torrent tracker - there is. The version is needed
12.1.0 build 3272444, because the patched exe file of this version. You can try another one at your own peril and risk.
2. Create a virtual machine and install an operating system on it. Your humble servant used Windows 7, it works more stable and less demanding on resources.
3. Install VMware Tools. We start the virtual machine. Next, go to "Virtual Machine" -> "Install VMware Tools package ...". An installer CD appears in the virtual machine. Run the installer, install with the default settings.
4. Change vmware-vmx.exe to a file from the archive. (Default path: C: \ Program Files (x86) \ VMware \ VMware Workstation \ x64 \ vmware-vmx.exe)
5. Copy the BIOS image to the folder with the virtual machine. You can copy it to another folder, only then you need to write the full path to the file in the settings file.
6. Edit the file with the virtual machine settings (file with the .vmx extension) using any text editor. Add lines:
Code:
monitor_control.restrict_backdoor = "true"
cpuid.1.ecx = "0 ---: ----: ----: ----: ----: ----: ----: - --- "
bios440.filename = "6006.ROM"
isolation.tools.copy.disable = "TRUE"
isolation.tools.dnd.disable = "TRUE"
isolation.tools.paste.disable = "TRUE"
7. Install the required program and try to run it.
Please note that the VMware Tools package must be installed BEFORE replacing the exe-file and editing the virtual machine settings. Otherwise, the installer will say that it needs to be installed only on the virtual machine and will cancel the installation. And without the installed package, some important functions are not available, for example, working with 3D graphics.
Conclusion
Modern antifraud systems can easily detect work from a virtual machine or an antidetext browser, as well as MAC address used and set by the system, DNS, IP address (its purity), fingerprint, cookies, hardware identifiers, installed programs and plugins, ports RDP, vpn, proxy and tunnels.
That is, changing the parameters to unique ones is required and is necessary every time after using (working out the material) - receiving a declline or detecting actions associated with any type of fraud, including hacking and carding.