July 7, 2023, 3:51 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


Hello, cybersecurity enthusiasts and white hackers!



Today, I just want to focus my research on another malware development trick: enum processes and find PID via WTSEnumerateProcesses. It is a common technique that can be used by malware for AV evasion also.


WTSEnumerateProcessesA win api


The WTSEnumerateProcessesA function is a Windows API function that retrieves information about the active processes on a specified terminal server:


BOOL WTSEnumerateProcessesA(
WTS_CURRENT_SERVER_HANDLE hServer,
DWORD Reserved,
DWORD Version,
PWTS_PROCESS_INFOA *ppProcessInfo,
DWORD *pdwCount
);

WTSEnumerateProcessesA …

api av evasion cybersecurity development evasion find focus hackers hello malware malware analysis malware development processes research simple

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Lead Technical Product Manager - Threat Protection

@ Mastercard | Remote - United Kingdom

Data Privacy Officer

@ Banco Popular | San Juan, PR

GRC Security Program Manager

@ Meta | Bellevue, WA | Menlo Park, CA | Washington, DC | New York City

Cyber Security Engineer

@ ASSYSTEM | Warrington, United Kingdom

Privacy Engineer, Technical Audit

@ Meta | Menlo Park, CA