Commit aded87e3 by mmorenog

Merge pull request #37 from merces/master

Process memory working set size anti-debug trick
parents 32c66ff5 87400d6c
...@@ -586,4 +586,15 @@ rule Check_FindWindowA_iat { ...@@ -586,4 +586,15 @@ rule Check_FindWindowA_iat {
pe.imports("user32.dll","FindWindowA") and ($ollydbg or $windbg) pe.imports("user32.dll","FindWindowA") and ($ollydbg or $windbg)
} }
rule DebuggerCheck__MemoryWorkingSet : AntiDebug DebuggerCheck {
meta:
author = "Fernando Mercês"
date = "2015-06"
description = "Anti-debug process memory working set size check"
reference = "http://www.gironsec.com/blog/2015/06/anti-debugger-trick-quicky/"
condition:
pe.imports("kernel32.dll", "K32GetProcessMemoryInfo") and
pe.imports("kernel32.dll", "GetCurrentProcess")
}
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment