• 🌙 Community Spirit

    Ramadan Mubarak! To honor this month, Crax has paused NSFW categories. Wishing you peace and growth!

Zagreus Ransomware v2.0.9 (1 Viewer)

Currently reading:
 Zagreus Ransomware v2.0.9 (1 Viewer)

Recently searched:

ghost88

Member
LV
3
Joined
Sep 3, 2021
Threads
27
Likes
81
Awards
7
Credits
6,365©
Cash
0$
IMG 20240713 143122 955


IMG 20240713 143123 270

Link:
https://mega.nz/file/8rxnjabY#CGPhFy682mSXDcnS_DB9LO0SynQtFZA9VliEA3FSn7Q
 

zhonow

Member
LV
1
Joined
Apr 19, 2024
Threads
10
Likes
21
Awards
5
Credits
3,806©
Cash
0$
also to add, matches these too:

Matches rule Powershell Defender Disable Scan Feature by Florian Roth (Nextron Systems) at Sigma Integrated Rule Set (GitHub)
Detects requests to disable Microsoft Defender features using PowerShell commands

Matches rule Windows Defender Definition Files Removed by frack113 at Sigma Integrated Rule Set (GitHub)
Adversaries may disable security tools to avoid possible detection of their tools and activities by removing Windows Defender Definition Files

Matches rule Tamper Windows Defender - ScriptBlockLogging by frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems) at Sigma Integrated Rule Set (GitHub).

Matches rule Powershell Defender Exclusion by Florian Roth (Nextron Systems) at Sigma Integrated Rule Set (GitHub)
Detects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets

Matches rule Windows Defender Exclusions Added - PowerShell by Tim Rauch, Elastic (idea) at Sigma Integrated Rule Set (GitHub)
Detects modifications to the Windows Defender configuration settings using PowerShell to add exclusions

Matches rule Non Interactive PowerShell Process Spawned by Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements) at Sigma Integrated Rule Set (GitHub)
Detects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.

source:virustotal and anyrun
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Tips
Recently searched:

Similar threads

Users who are viewing this thread

Top Bottom