Win32.Ransom.BlueSky MVID-2022-0632...

- AV AC AU C I A
发布: 2022-08-15
修订: 2024-12-11

The BlueSky Win32.Ransom.BlueSky ransomware looks for and executes arbitrary DLLs in its current working directory. Therefore, we can hijack a DLL, execute our own code, and control and terminate the malware pre-encryption. The exploit DLL checks if the current directory is "C:\Windows\System32" and if not we grab our own process ID and terminate. All basic tests were conducted successfully in a virtual machine environment.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息