10 ms·
There's a claim over on Mastodon from Kevin Beaumont that the file is different on every customer he´s received the file from. https://cyberplace.social/@Gossi
by neffy 2y ago
There's a claim over on Mastodon from Kevin Beaumont that the file is different on every customer he´s received the file from.
https://cyberplace.social/@GossiTheDog/112812454405913406 https://cyberplace.social/@GossiTheDog/112812454405913406
(scroll down a little)
- drewg123 2y agoI thought windows required all kernel modules to be signed..? If there are multiple corrupt copies, rather than just some test escape, how could they have passed the signature verification and been loaded by the kernel?
- dist-epoch 2y agoThis is not even a valid executable. Most likely is not loaded as a driver binary, but instead is some data file used by the CrowdStrike driver.
- Izkata 2y agoSeems like a data file: https://news.ycombinator.com/item?id=41004103 https://news.ycombinator.com/item?id=41004103