mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
1.7 KiB
1.7 KiB
| ID | X0015 |
| Aliases | |
| Platforms | Windows |
| Year | 2011 |
Redhip
An information stealer.
Behaviors
| Name | Use |
|---|---|
| Sandbox Detection | Redhip detects all publicly available automated malware analysis workbenches (ThreatExpert, JoeBox, etc.). [1] |
| Virtual Machine Detection | Redhip detects VMWare, Virtual PC and Virtual Box. It also detects VM environments in general by considering timing lapses. [1] |
| Debugger Detection | Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [1] |
| Debugger Evasion | Redhip uses general approaches to detecting user level debuggers (e.g., Process Environment Block 'Being Debugged' field), as well as specific checks for kernel level debuggers like SOFICE. [1] |
| Executable Code Compression | Redhip samples are packed with different custom packers. [1] |
References
[1] https://www.fireeye.com/blog/threat-research/2011/01/the-dead-giveaways-of-vm-aware-malware.html