View Single Post
  #4  
Old 02-19-2017, 17:25
gigaman gigaman is offline
Friend
 
Join Date: Jun 2002
Posts: 87
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 14 Times in 11 Posts
gigaman Reputation: 4
Persistence in registry is quite common - e.g. in one of the auto-run entries which respawn the code after reboot (via a common system module and some javascript code which itself is only in registry).
(Now since the registry hive is also on disk, you could argue that it's not a real fileless malware, but that's just terminology :-))
Reply With Quote