Page values for "Ema-1099"

Jump to navigation Jump to search

"Associations" values

Association_TypeBehavior
Associated_Pagedebugger detect & evade

"Behavior_Instances" values

Associated_Behaviordebugger detect & evade

"Pages" values

NameProcess Environment Block (PEB)
Title_IconBehaviorInstance-Windows.png
Description

The Process Environment Block (PEB) is a Windows data structure associated with each process that contains several fields, one of which is "BeingDebugged". Testing the value of this field in the PEB of a particular process can indicate whether the process is being debugged; this is equivalent to using the kernel32!IsDebuggerPresent API call.

"References" values

Reference_Date2011-01-27
Malware_FamilyRebhip
Reference_URLhttps://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html