Page values for "Ema-1090"

Jump to navigation Jump to search

"Associations" values

Association_TypeBehavior
Associated_Pagevirtual machine detect & evade

"Behavior_Instances" values

Associated_Behaviorvirtual machine detect & evade

"Pages" values

NameGuest Process Testing
Title_IconBehaviorInstance-Windows.png
Description

Virtual machines offer guest additions that can be installed to add functionality such as clipboard sharing. Detecting the process, via its name or other methods, responsible for these tasks is a technique employed by malware for detecting whether it is being executed in a virtual machine.

"References" values

Reference_Date2015-01-27
Malware_FamilyRebhip
Reference_URLhttps://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html