ÈÈÃÅ£º 51µ¥Æ¬»ú | 24Сʱ±Ø´ðÇø | µ¥Æ¬»ú½Ì³Ì | µ¥Æ¬»úDIYÖÆ×÷ | STM32 | Cortex M3 | Ä£Êýµç×Ó | µç×ÓDIYÖÆ×÷ | ÒôÏì/¹¦·Å | ²ð»úÀÖÔ° | Arduino | ǶÈëʽOS | ³ÌÐòÉè¼Æ
rule superadmin_suspect meta: description = "Detects superadmin.exe by name and suspicious characteristics" strings: $name = "superadmin.exe" nocase $s1 = "CreateProcessAsUser" wide $s2 = "AdjustTokenPrivileges" wide condition: $name and (filesize < 5MB) and (1 of ($s*))
This write‑up is for defensive security use. Do not execute or rename superadmin.exe without containment. When in doubt, consult your incident response team. superadmin.exe
СºÚÎÝ|51ºÚµç×ÓÂÛ̳
|
¹ÜÀíÔ±QQ:125739409;¼¼Êõ½»Á÷QQȺ281945664
Powered by µ¥Æ¬»ú½Ì³ÌÍø