
Prodigy
•
159 Messages
•
4.7K Points
Terminator malware not been detected
I had submitted a sample for reclassification but after analysis Trend micro is showing that file as normal file.
[TM-3015963-K4N7W8] Results for the File Submitted for Reclassification Ref:04500000542
This sample is detected by Eset as PUA Vulnerable Zemana driver and has other detections as well over virustotal website. Some of these are Spyboy vulnerable driver.
Here is the virustotal website link-
SHA 256- 543991ca8d1c65113dff039b85ae3f9a87f503daec30f46929fd454bc57e5a91
Trend Micro did a research extensively recently over vulnerable zemana driver. To quote a trend micro post "Terminator.exe is the re-created "SpyBoy" tool.
The tool abuses the zam64.sys driver to terminate all EDR/XDR/AV processes."
I believe that this sample is related or similar to this one.
Anime_007
Prodigy
•
159 Messages
•
4.7K Points
5 months ago
@tm_kree @tm_darlene someone from Trend Micro check the information that I provided.
4
0
tm_prima
Trend Security Expert
•
71 Messages
•
1.5K Points
5 months ago
Hi @Anime_007
We appreciate you alerting us this issue. This case is currently under investigation and already escalated to our designated team.
Rest assured that we will give you an update as soon as we receive their findings regarding on this problem. We understand that your time is valuable, and we genuinely appreciate your patience in understanding.
(edited)
9