Deleting the Defenders: A Commodity BYOVD Toolkit That Erases Host Safeguards
Threat Intelligence Spotlight Executive Summary VMRay Labs has analyzed a family of malicious WinRAR self-extracting archives that act as droppers. Each one unpacks several helper tools and a password protected archive into a temporary folder, then executes a batch script. The script identifies Windows security components on the host, disables Windows Update to prevent theirVMRayRead More