Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
IT NachrichtenHere’s the Samsung Galaxy Buds On and Their Features(01.10.2026 um 02:41 Uhr)
••••
Hacking & PentestingAlbert Hacker - Nachrichten & Infos - Basketball - Eurosport(30.09.2026 um 14:22 Uhr)
•
AI & KI NachrichtenElon Musk’s Grokipedia has a ‘newly refreshed’ design(01.10.2026 um 02:23 Uhr)
•••••
IT NachrichtenHere’s the Samsung Galaxy Buds On and Their Features(01.10.2026 um 02:41 Uhr)
••••
Hacking & PentestingAlbert Hacker - Nachrichten & Infos - Basketball - Eurosport(30.09.2026 um 14:22 Uhr)
•
AI & KI NachrichtenElon Musk’s Grokipedia has a ‘newly refreshed’ design(01.10.2026 um 02:23 Uhr)
•••••
Intelligence View
⚡ tsecurity.de Intelligence

Ransom.REvil MVID-2022-0600 Code Execution

REvil ransomware looks for and executes DLLs in its current directory. Therefore, we can hijack a DLL, execute our own code, and control and terminate the…

Beitrag
0
Seite
0
↗ Quelle (packetstormsecurity.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
REvil ransomware looks for and executes DLLs in its current directory. Therefore, we can hijack a DLL, execute our own code, and control and terminate the malware pre-encryption. The exploit DLL checks if the current directory is "C:\Windows\System32" and if not we grab our process ID and terminate. We do not need to rely on hash signatures or third-party products as the malware's flaw does the work for us. Endpoint protection systems and or antivirus can potentially be killed prior to executing malware, but this method cannot as there's nothing to kill the DLL that just lives on disk waiting. From a defensive perspective you can add the DLLs to a specific network share containing important data as a layered approach. All basic tests were conducted successfully in a virtual machine environment.

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph3 Knoten / 2 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Ransom.REvil MVID-2022-0600 Code Execution

Thematisch verwandte Begriffe: RansomREvil, MVID20220600, Code, Execution · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag