cruelsister Level 43 Thread author Verified Honorary Member Top Poster Content Creator Well-known Forum Veteran Apr 13, 2013 3,272 25,108 4,188 NYC Jul 14, 2016 #1 Used is a modified JuicyLemon ransomware file. Reactions: LAGUN, tonibalas, XhenEd and 14 others
_CyberGhosT_ Level 53 Verified Honorary Member Top Poster Content Creator Well-known Aug 2, 2015 4,286 27,654 5,188 56 Central US Jul 14, 2016 #2 Awesome heads-up. What are good products for preventing or cleaning up "SVChost Infections" ? Thanks CruelSister Reactions: SHvFl and Cats-4_Owners-2
Awesome heads-up. What are good products for preventing or cleaning up "SVChost Infections" ? Thanks CruelSister
SHvFl Level 35 Verified Honorary Member Top Poster Content Creator Well-known Forum Veteran Nov 19, 2014 2,364 17,613 3,390 Europe Jul 14, 2016 #3 Very interesting video. Thanks for sharing. Reactions: _CyberGhosT_
N NullByte Jul 14, 2016 #4 Looks like this technique is very similar to userinit injection made by ZeusBotnet but here it's using svchost. What if you use winlogon to make an install on boot
Looks like this technique is very similar to userinit injection made by ZeusBotnet but here it's using svchost. What if you use winlogon to make an install on boot