Thứ Tư, Tháng Năm 18, 2022
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

AvosLocker Ransomware variant uses new trick to disable antivirus protection

3 Tháng Năm, 2022
in Tech
0
AvosLocker Ransomware variant uses new trick to disable antivirus protection
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

Download VSDC Video Editor Pro 7

Download VSDC Video Editor Pro 7

17 Tháng Năm, 2022
không gian bình yên giữa lòng Đồng Hới

không gian bình yên giữa lòng Đồng Hới

17 Tháng Năm, 2022
Russia may have withdrawn border defenses from Kharkiv

Russia may have withdrawn border defenses from Kharkiv

17 Tháng Năm, 2022
Information about the Kubet disc shock hack tool that players need to know

Information about the Kubet disc shock hack tool that players need to know

17 Tháng Năm, 2022
How to Screen Share on Google Duo on Android and the Web

How to Screen Share on Google Duo on Android and the Web

17 Tháng Năm, 2022
Beautiful dog pictures

Beautiful dog pictures

17 Tháng Năm, 2022

AvosLocker Ransomware

Cybersecurity researchers have revealed a new variant of ransomware AvosLocker disable anti-virus solutions to avoid detection after compromising the target network by taking advantage of unpatched security flaws.

Trend Micro researchers Christoper Ordonez and Alvin Nieto said in an analysis Monday: “This is the first pattern we’ve observed from the United States with the ability to neutralize defenses by using use the legitimate Avast Anti-Rootkit Driver file (asWarPot.sys)” .

“Additionally, the ransomware is also capable of scanning multiple endpoints for Log4j (Log4shell) vulnerabilities using the Nmap NSE script.”

AvosLocker, one of the newer ransomware families to fill the void left by REvil, has been implicated in several attacks targeting critical infrastructure in the US, including financial services and key facilities government.

As a ransomware-as-a-service (RaaS)-based federation first discovered in July 2021, AvosLocker goes beyond double extortion by auctioning off data stolen from ransomware. multiplier if the targeted object refuses to pay the ransom.

Other targeted victims claimed by the ransomware group are believed to be in Syria, Saudi Arabia, Germany, Spain, Belgium, Turkey, UAE, UK, Canada, China and Taiwan, according to an advisory issued by the US Federal Bureau of Investigation. of the Bureau of Investigation (FBI) in March 2022.

Telemetry data collected by Trend Micro shows that the food and beverage sector was the most impacted industry from July 1, 2021 to February 28, 2022, followed by the technology vertical , finance, telecommunications and media.

The starting point for the attack is said to have been facilitated by exploiting a remote code execution vulnerability in Zoho’s ManageEngine ADSelfService Plus software (CVE-2021-40539) to run an HTML application (HTA). ) is hosted on the remote server.

“HTA executed a obfuscated PowerShell script containing a shellcode, capable of connecting back to [command-and-control] the researchers explained.

This includes retrieving the ASPX web shell from the server as well as the installer for the AnyDesk remote desktop software, which is used to deploy additional tools for local network scanning, termination security software and ransomware offloading.

Some of the components copied to the infected endpoint were an Nmap script that scans the network for Log4Shell remote code execution vulnerabilities (CVE-2021-44228) and a mass deployment tool called PDQ for distribution. malicious batch script to multiple endpoints.

For its part, the batch script is equipped with many capabilities that allow it to disable Windows Update, Windows Defender and Windows Error Recovery, in addition to preventing the secure boot execution of security products, creating an account new admin and launch the ransomware binary.

Also used was aswArPot.sys, a legitimate Avast anti-rootkit driver, to kill processes associated with various security solutions by weaponizing a now-fixed vulnerability. in the driver that the Czech company resolved in June 2021.

“The decision to select a specific rootkit driver file was because of its ability to execute in kernel mode (thus operating at high privileges),” the researchers point out. “This variant also has the ability to modify other details of installed security solutions, such as disabling legal notices.”

.

Previous Post

Download SlickEdit Pro 2021 – Detailed installation instructions

Next Post

Nature wallpapers

Admin Natuts

Admin Natuts

Related Posts

Information about the Kubet disc shock hack tool that players need to know

Information about the Kubet disc shock hack tool that players need to know

17 Tháng Năm, 2022
How to Screen Share on Google Duo on Android and the Web

How to Screen Share on Google Duo on Android and the Web

17 Tháng Năm, 2022
Beautiful dog pictures

Beautiful dog pictures

17 Tháng Năm, 2022
Coi chừng! Tin tặc bắt đầu khai thác lỗ hổng tường lửa Zyxel gần đây RCE

Coi chừng! Tin tặc bắt đầu khai thác lỗ hổng tường lửa Zyxel gần đây RCE

17 Tháng Năm, 2022
Use AI to turn sketches into real photos

Use AI to turn sketches into real photos

16 Tháng Năm, 2022
Volume buttons don’t work on iPhone [6 Proven Fixes]

Volume buttons don’t work on iPhone [6 Proven Fixes]

16 Tháng Năm, 2022
Load More
Next Post
Nature wallpapers

Nature wallpapers

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

Download VSDC Video Editor Pro 7
Software

Download VSDC Video Editor Pro 7

17 Tháng Năm, 2022
không gian bình yên giữa lòng Đồng Hới
Travel

không gian bình yên giữa lòng Đồng Hới

17 Tháng Năm, 2022
Russia may have withdrawn border defenses from Kharkiv
News

Russia may have withdrawn border defenses from Kharkiv

17 Tháng Năm, 2022
Information about the Kubet disc shock hack tool that players need to know
Tech

Information about the Kubet disc shock hack tool that players need to know

17 Tháng Năm, 2022
How to Screen Share on Google Duo on Android and the Web
Tech

How to Screen Share on Google Duo on Android and the Web

17 Tháng Năm, 2022
Beautiful dog pictures
Tech

Beautiful dog pictures

17 Tháng Năm, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân Chỉnh ảnh data domain download du lịch fshare game game show hosting HÌNH XĂM IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin lừa đảo messenger miễn phí mua sắm Máy ảnh mạng mồi tiềm thức network nghệ thuật nhà Trần quảng cáo review tháp phân tầng xã hội tiếng anh tiện ích Trần Thủ Độ tên miền từ vựng viettel word xã hội Đơn giản đánh bạc

Recent News

Download VSDC Video Editor Pro 7

Download VSDC Video Editor Pro 7

17 Tháng Năm, 2022
không gian bình yên giữa lòng Đồng Hới

không gian bình yên giữa lòng Đồng Hới

17 Tháng Năm, 2022

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem