The Threat Response Unit (TRU) team of eSentire identified pirated Windows Operating System (OS) backdoored with CryptoMiner and Xtreme RAT. The TRU found that there were several malicious Windows services on the system which modified system permissions, disabled Windows defenders, and retrieved payloads from msz[.]su. According to the team, this behavior is identical to the one prescribed by Minerva Labs in mid-2021, which introduced ways to bypass Windows defender. The Security Operations Center (SOC) alarmed the customers of the malicious endpoint activity and offered suggestions for remediation and further forensic investigation.
Inscrivez-vous par courriel maintenant pour le Stock de Promotion hebdomadaire
100% free, Unsubscribe any time!Add 1: Room 605 6/F FA YUEN Commercial Building, 75-77 FA YUEN Street, Mongkok KL, HongKong Add 2: Room 405, Building E, MeiDu Building, Gong Shu District, Hangzhou City, Zhejiang Province, China
Whatsapp/Tel: +8618057156223 Tél. : + 33 (0) 3 88 88 20: 0086 571 86729517 Tel à HK: 00852 66181601
Courriel:: [email protected]