Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
Interesting malware analysis
Message
De
15/09/2020 13:25:20
 
 
À
15/09/2020 10:50:32
Information générale
Forum:
Internet
Catégorie:
Sécurité
Divers
Thread ID:
01676132
Message ID:
01676135
Vues:
42
>>https://blog.huntresslabs.com/hiding-in-plain-sight-556469e0a4e?gi=7a57b7ba5adc
>>https://blog.huntresslabs.com/hiding-in-plain-sight-part-2-dfec817c036f
>>
>>Some clever techniques in use.
>
>Yeah, that's some pretty neat stuff. Clever.

DNS over HTTPS is something I hope to avoid as long as possible or keep under own control, not only for such stuff, but for a working Pi-Hole - But currently it seems to be en vogue to target it.

Dynamic patching of the AMSI without SU/Admin credentials smells of hexapod critter, perhaps should not be allowed dynamically at all.

The command creation via split not resulting in a file to load and keep on HD while executing is ugly - uncertain something similar could be done via only memory based file.
Précédent
Suivant
Répondre
Fil
Voir

Click here to load this message in the networking platform