20180509

Process Doppelgänging(プロセス ドッペルギャンギング)

「Process Doppelgänging(プロセス ドッペルギャンギング)」

Black Hat Europe 2017
Process Doppelgänging

マルウェア「SynAck」


【外部リンク】
https://thehackernews.com/2018/05/synack-process-doppelganging.html

First-Ever Ransomware Found Using ‘Process Doppelgänging’ Attack to Evade Detection
 Monday, May 07, 2018  Mohit Kumar




An interesting thing about SynAck is that this ransomware does not infect people from specific countries, including Russia, Belarus, Ukraine, Georgia, Tajikistan, Kazakhstan, and Uzbekistan.
--

注目の投稿

Shadowserver Foundation http://65.49.1.117/

Shadowserver Foundation port 14491 discarded for LINK-FRMWRK: NO ENTRY IN LOOKUP TABLE TO COMPLETE OPERATION, GigaEthernet2.0 Wistron Neweb ...

人気の投稿