Writeups

The Gentlemen Ransomware Notes

+ SHA256: 22b38dad7da097ea03aa28d0614164cd25fafeb1383dbc15047e34c8050f6f67 + MD5: 7a262d4cbbc4808932b6af42c4041f06 + SHA1: 9e951cf2f868b71aaaa05966d8eb96d333b80106 + CRC32: a287bcbe + Entropy: 6.58

challenge

This is a challenge from https://malops.io/challenges/sagerunex

Analysis of a Signed Silver Fox Group AV/EDR Killer Kernel Driver

A small 64-bit Windows kernel driver (driver.sys) was analyzed. Despite being code-signed by **CR Connect (Tokyo) LLP**, it functions as a straightforward AV/EDR process killer.

reverser.space
Loading