TROJAN: Equation Group PrivLib Exploitation Library Detected

This signature detects the PrivLib exploitation library used by Equation Group to infect users. This library is used in malware samples to provide easy exploitation of victim systems.

Short Name
TROJAN:EQUATIONGRP-PRIVLIB
Severity
Major
Recommended
True
Recommended Action
Drop
Category
TROJAN
Keywords
Detected Equation Exploitation Group Library PrivLib
Release Date
02/25/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?