Remove IPv6 Remove Malware Remove Network Remove SMB
article thumbnail

MadoMiner Part 2 - Mask

AlienVault

In addition, take care with this portion of the malware. Malware Analysis. CVE-2017-0143, SMB exploit. CVE-2017-0146, SMB exploit. Sogou.exe is the payload that contains the CPUInfo scanner, however, it has been set to scan for IPV6 addresses. However, Sogou.exe is more of a dropper than the full malware itself.

Malware 40