-
Notifications
You must be signed in to change notification settings - Fork 31
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
检测绕过 #35
Comments
能再看看这个样本嘛?冰盾内置规则似乎没法检测到该样本的 镂空进程 和 修改线程上下文 的行为,解压密码依然是infected |
https://www.henry-blog.life/henry-blog/shellcode-jia-zai-qi/jin-cheng-lou-kong-zhu-ru-kui-lei-jin-cheng |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
冰盾似乎无法检测该样本篡改进程(colorcpl.exe )内存的行为
此外该样本似乎也绕过了冰盾自带的父进程欺骗检测?(此进程不应由explorer.exe启动)
样本(解压密码infected):https://wwjw.lanzouq.com/iu3IW2fgzape
The text was updated successfully, but these errors were encountered: