Skip to content

Commit

Permalink
Adding NvSmartMax, FormDLL, SafeStore32 entries
Browse files Browse the repository at this point in the history
  • Loading branch information
wietze committed Sep 4, 2023
1 parent c55a968 commit 4e1e6ad
Show file tree
Hide file tree
Showing 3 changed files with 42 additions and 0 deletions.
15 changes: 15 additions & 0 deletions yml/3rd_party/nvidia/nvsmartmax.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
---
Name: nvsmartmax.dll
Author: Wietze Beukema
Created: 2023-09-04
Vendor: Nvidia
ExpectedLocations:
- '%PROGRAMFILES%\NVIDIA Corporation\Display'
VulnerableExecutables:
- Path: '%PROGRAMFILES%\NVIDIA Corporation\Display\nvSmartEx.exe'
Type: Sideloading
SHA256:
- 523d28df917f9d265cd2c0d38df26277bc56a535145100ed82e6f5fdeaae7256
Resources:
- https://www.cybereason.com/blog/research/deadringer-exposing-chinese-threat-actors-targeting-major-telcos
- https://www.mandiant.com/sites/default/files/2022-02/rt-apt41-dual-operation.pdf
13 changes: 13 additions & 0 deletions yml/3rd_party/sophos/safestore32.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
Name: safestore32.dll
Author: Wietze Beukema
Created: 2023-09-04
Vendor: Sophos
ExpectedLocations:
- '%PROGRAMFILES%\Sophos\Sophos Anti-Virus'
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ssr32.exe'
Type: Sideloading
Condition: 'Assumes version 1.3.0.1 or before, included in Sophos Endpoint installations prior to version 2021.3'
Resources:
- https://symantec.broadcom.com/hubfs/Attacks-Against-Government-Sector.pdf
14 changes: 14 additions & 0 deletions yml/microsoft/external/formdll.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
Name: formdll.dll
Author: Wietze Beukema
Created: 2023-09-04
Vendor: Microsoft
ExpectedLocations:
- '%PROGRAMFILES%\Common Files\Microsoft Shared\NoteSync Forms'
VulnerableExecutables:
- Path: '%PROGRAMFILES%\Common Files\Microsoft Shared\NoteSync Forms\inkform.exe'
Type: Sideloading
SHA256:
- 0e545a54f3cfef84bb59be1a95453ae4b34b5464b0f5ca618a0da2e4c97c7526
Resources:
- https://any.run/report/d9c7f6d4ec08d961c20dac1b6422b3fbec5c6a8d9dc67d1f604835b36c5f224e/ae068531-92db-497d-b0cb-c0b1af5476f1

0 comments on commit 4e1e6ad

Please sign in to comment.