New Ursnif Malware Campaign Uses Fileless Infection to Avoid Detection

Discussion in 'malware problems & news' started by guest, Jan 24, 2019.

  1. guest

    guest Guest

    New Ursnif Malware Campaign Uses Fileless Infection to Avoid Detection
    January 24, 2019
    https://www.bleepingcomputer.com/ne...n-uses-fileless-infection-to-avoid-detection/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    What I hate about these type of articles is that they fail to mention that malware still needs to run inside a certain process. And the process that it's running in they don't actually mention clearly, so it's for me to guess. But it's probably wmic.exe or powershell.exe, so if you restrict those, then I guess you're good.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.