Get a Pentest and security assessment of your IT network.

News

Winnti 1.0 technical analysis

Malware authors place a malicious library in the %WINDIR% folder. The same folder also hosts the program explorer.exe. This enables the attackers to ensure that the malicious DLL is loaded at system startup. The malicious library is designed to load the original winmm.dll from the %windIR%System32 folder. When a program that depends on the original library is loaded, the DLL will be loaded when this program is executed instead of the. original library that is located at %windir%.System32winmm.DLL is a Windows system library which provides multimedia functions.”]

Source: https://securelist.com/winnti-1-0-technical-analysis/37002/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin