Page values for "Ema-1100"

Jump to navigation Jump to search

"Associations" values

Association_TypeBehavior
Associated_Pagedebugger detect & evade

"Behavior_Instances" values

Associated_Behaviordebugger detect & evade

"Pages" values

NameAPI Call: IsDebuggerPresent
Title_IconBehaviorInstance-Windows.png
Description

The kernel32!IsDebuggerPresent API call checks the Process Environment Block to see if the calling process is being debugged. This is one of the most basic and common ways of detecting debugging.

"References" values

Reference_Date2011-01-27
Malware_FamilyRebhip
Reference_URLhttps://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html