
TrojanDropper/PS.Maloader.d
TrojanDropper/PS.Maloader.d
Since its emergence in 2018, the "DriveLife" virus has spawned multiple variants and continuously refined its techniques to evade detection and removal by security software.
The virus exploits multiple high-risk vulnerabilities, including EternalBlue and SMBGhost, to compromise and infect hosts running Windows and Linux.
After a successful breach, it not only downloads miner files for cryptocurrency mining, but also releases a propagation module to continue compromising other endpoints.
Moreover, the PowerShell scripts used by the virus are obfuscated through multiple layers to evade detection by security software.
