Уровень 0 · материалов: 2
В кластер входят документы, описывающие конкретные технические механизмы обхода антивирусного ПО и систем анализа, и не входят документы, посвященные методам распространения или социальной инженерии вредоносных программ.
Общие признаки: вредоносное ПО, обход антивирусного анализа, скрытие присутствия в системе, технические способы обхода защиты
Группа выше: Обнаружение, удаление и обход защиты
Смысл: The main idea is to warn about the Rombertik malware, which differs from typical viruses by actively destroying the system (MBR or user files) specifically when it detects antivirus analysis, utilizing extreme obfuscation to evade security experts.
Rombertik is a destructive malware that destroys the computer's boot record or encrypts user files if it detects it is being analyzed by antivirus software.
Смысл: The text explains a stealthy malware execution technique called 'Process Doppelgänging' that bypasses antivirus software by using NTFS transactions to load malicious code into memory without leaving traces on the disk.
A critical Windows vulnerability called Process Doppelgänging allows malware to run undetected by antivirus software by leveraging NTFS transactions to hide malicious code in memory.