process_chameleon icon indicating copy to clipboard operation
process_chameleon copied to clipboard

A process overwriting its own PEB to make an illusion that it has been loaded from a different path.

Process Chameleon

Build status

This is my "lil_calc" PoC presented on the video:
Test with ProcessExplorer vs TaskManager
It is not FUD, but it can fool some tools and it can be used as a test case. The process overwrites its own PEB to create an illusion, that it has been loaded from a different path.