  1. M. Smoot

    Good Morning Tom, nice write up. Noticed however that your article notes, “The attack works against fully patched Windows 10 and previous Windows versions, Flashpoint said.” Can you point me to where this ref was taken from? I reviewed the Flashpoint hyperlink (Jan 26) you listed and it only makes ref to Win 7. Thanks!

  2. Justin

    Question. This:
    “Here Dridex executes commands that copies the recdisc[.]exe binary from Windows\System32\recdisc[.]exe and loads it into a new directory it creates called Windows\System32\6886.”

    In order to create the new directory and copy itself within the Windows directory, it would need elevated privilages. Does the infection require initial elevation by the user?


