Phalanx Rootkit
select * from file where path in ('/usr/share/.home*', '/usr/share/.home*/tty', '/etc/host.ph1', '/bin/host.ph1');View Full Query Detailsselect * from file where path in ('/usr/share/.home*', '/usr/share/.home*/tty', '/etc/host.ph1', '/bin/host.ph1');View Full Query Detailsselect * from registry where key='HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\PolicyScope'View Full Query Details
select * from registry where key like 'HKEY_USERS\%\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\PolicyScope'View Full Query Details
select * from portage_packages;View Full Query Details
select * from launchd where name = 'PremierOpinion.plist' or name = 'PremierOpinionAgent.plist';View Full Query Details
select * from process_envs;View Full Query Details
select * from process_memory_map;View Full Query Details
select * from launchd where name = 'pronto.notification.plist' or name = 'pronto.update.plist';View Full Query Details
select * from registry where path like 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\Default\%' AND name IN ('WeakSha1ThirdPartyFlags','WeakMd5ThirdPartyFlags') AND type = 'REG_DWORD' AND data not like '-2%';View Full Query Detailsselect * from launchd where name = 'com.apple.PubSabAgent.plist';View Full Query Details