EC-Council Certified Ethical Hacker (CEH) v12Malware ThreatsHard
A security analyst is investigating a suspected malware infection on a corporate workstation. During the investigation, the analyst uses a debugger to step through the malware's code. However, the malware detects the debugger and terminates its execution, preventing further analysis. This behavior is a clear indication that the malware is employing which specific anti-analysis technique?
- AAnti-debugging
- BPayload encryption
- CAnti-VM (Virtual Machine) detection
- DCode obfuscation
Show answer & explanationAnswer & explanation
Correct answer: A. Anti-debugging
Anti-debugging techniques are employed by malware to detect if it is being executed within a debugger. Upon detection, the malware can alter its behavior, terminate, or even actively try to crash the debugger, thereby hindering analysis. The scenario explicitly states the malware 'detects the debugger and terminates its execution'.
Why the other options are wrong
- B. Payload encryption protects the payload but doesn't detect the analysis environment itself.
- C. Anti-VM detection checks for virtualized environments, not specifically debuggers.
- D. Code obfuscation makes code harder to understand but doesn't necessarily detect and react to a debugger.
Anti-Debugging
A set of techniques used by malware to detect the presence of a debugger and react in a way that hinders analysis, such as terminating or altering execution.
- Checks for debugger-specific artifacts (e.g., process names, breakpoints).
- Can lead to malware termination, altered execution flow, or system crashes.
- Makes dynamic analysis more challenging for researchers.
Memory trick: Malware Doesn't Want to Be Debugged.