LOLDrivers high experimental sigma

Driver Load - 360netmon_wfp.sys

Detects loading of driver 360netmon_wfp.sys via hash. Qihoo 360netmon_wfp.sys is a signed kernel driver documented by ESET as the driver abused by the GentleKiller Network Blocker variant used in Gentlemen ransomware intrusions. The sample is associated with ESET detection Win64/VulnDriver.Qihoo360.A.

View Source

Detection Logic

{
  "selection_hashes": {
    "Hashes
| contains": [
      "MD5=40f64b91348bed955acf8551853b72a8",
      "SHA1=9ad51ad97c01e97ab59214116740785e0f6320a8",
      "SHA256=3d769a5f1ad0d32fb4e06478d35401d9788bad1a477b813adbdf4fd93b2c2694",
      "IMPHASH=8961b79bdb35a91c4966a20141d1f406"
    ]
  },
  "condition": "selection_hashes"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...