LOLDrivers low experimental sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via name. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

View Source

Detection Logic

{
  "selection_name": {
    "ImageLoaded
| endswith": [
      "\\360netmon_wfp.sys"
    ]
  },
  "condition": "selection_name"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...