其他
史无前例:微软 SQL Server 被黑客组织安上了后门 skip-2.0(来看技术详情)
VMProtected 启动器
Winnti Group 的自定义打包程序
Skip-2.0
CPwdPolicyManager::ValidatePwdForLogin
CSECAuthenticate::AuthenticateLoginIdentity
ReportLoginSuccess
IssueLoginSuccessReport
FExecuteLogonTriggers
XeSqlPkg::sql_statement_completed::Publish
XeSqlPkg::sql_batch_completed::Publish
SecAuditPkg::audit_event::Publish
XeSqlPkg::login::Publish
XeSqlPkg::ual_instrument_called::Publish
和 Winnti Group 的关联
结论
ESET 此前发布的Winnti Goup 武器库白皮书 URL: https://www.welivesecurity.com/wp-content/uploads/2019/10/ESET_Winnti.pdf YARA 规则的GitHubURL: https://github.com/eset/malware-ioc/tree/master/winnti_group
奇安信代码卫士 (codesafe)
国内首个专注于软件开发安全的产品线。