endgameinc / eqllib

MIT License
158 stars 46 forks source link

Analytic for process injection via ld.so.preload #10

Closed ForensicITGuy closed 5 years ago

ForensicITGuy commented 5 years ago

Analytic to detect process injection via ld.so.preload file modification. This technique was observed during Rocke and Pancha Group cryptojacking campaigns.