Abstract: A computing device for determining a malicious code, comprising: a virtual information configured to generate a virtualization profile for a virtual machine to execute a target code detected using a terminal configuration information received from a target terminal; a determiner configured to preprocess at least one dynamic characteristic related to an avoid command for a virtualization system contained within the target code transmitted from the virtual machine of the target terminal, select at least one artificial neural network from a plurality of pre-trained artificial neural networks based on a characteristic value of the preprocessed at least one dynamic characteristic, and determine whether the target code is a malicious code using the selected artificial neural network.