Skip to content

Can't detect hollow process created by ursnif trojan #3

@shelovemee

Description

@shelovemee

Hi hasherezade,

Thanks for your great tool. I tested hollows_hunter, it can detect hollow process created by Agenttesla, fareit, formbook. However, it can't detect iexplore.exe created by ursnif trojan.
You can download the sample below,

http://www.mediafire.com/file/qr9yd9m4ef53nap/wqooz7_ursnif_iexplore.zip/file
78e76bab450a3794449e7673c2f4096c44e47587ae77b1987cab1a13cbb842b8

Another question. Is there a way to use hollows hunter to detect hollow process in Real-time?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions