Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

增强模板检测绕过 #36

Open
UnknownOooo opened this issue Dec 5, 2024 · 0 comments
Open

增强模板检测绕过 #36

UnknownOooo opened this issue Dec 5, 2024 · 0 comments

Comments

@UnknownOooo
Copy link

最近的样本中存在检测系统环境并执行不同行为的情况,故复现该问题需要同时安装 火绒 和 冰盾 才可以复现。

问题:在启用 增强模板 中的规则 “禁止关机(重启)” ,响应动作:询问(默认拦截)后,仍然无法阻止该样本的强制重启系统操作。

样本:https://wwjw.lanzouq.com/ihw3r2ha01lc (解压密码为:infected)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant