恶意软件利用受信任的Avast Anti-RootKit驱动程序来禁用安全软件-安全客 - 安全资讯平台
Tags
attack-pattern: Rootkit - T1014 Rootkit
Common Information
Type Value
UUID d3bb2c1b-14f6-4148-b070-42201d85875a
Fingerprint d9ffcb74097a60ca
Analysis status DONE
Considered CTI value 0
Text language
Published Nov. 26, 2024, midnight
Added to db Nov. 26, 2024, 8:12 a.m.
Last updated Dec. 2, 2024, 4:36 p.m.
Headline 恶意软件利用受信任的Avast Anti-RootKit驱动程序来禁用安全软件
Title 恶意软件利用受信任的Avast Anti-RootKit驱动程序来禁用安全软件-安全客 - 安全资讯平台
Detected Hints/Tags/Attributes 1/1/3
Source URLs
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 15 安全客-有思想的安全新媒体 https://api.anquanke.com/data/v1/rss 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details File 21
aswarpot.sys
Details File 7
kill-floor.exe
Details File 10
ntfs.bin