Hi hasherezade,
Thanks for your great tool. I tested hollows_hunter, it can detect hollow process created by Agenttesla, fareit, formbook. However, it can't detect iexplore.exe created by ursnif trojan.
You can download the sample below,
http://www.mediafire.com/file/qr9yd9m4ef53nap/wqooz7_ursnif_iexplore.zip/file
78e76bab450a3794449e7673c2f4096c44e47587ae77b1987cab1a13cbb842b8
Another question. Is there a way to use hollows hunter to detect hollow process in Real-time?