Malicious Process Detection: APT1 Software Running

This script is Copyright (C) 2013-2017 Tenable Network Security, Inc.

Synopsis :

Nessus detected potentially unwanted processes on the remote host.

Description :

The md5sum of one or more running processes on the remote Windows host
matches the signature distributed by Mandiant of software known to be
involved in corporate cyber espionage by a unit called APT1.

Verify that the remote processes are legitimate and authorized in your

See also :

Solution :

Uninstall the remote software if it does not match your security
policy, investigate your network for further signs of a breach

Risk factor :


Family: Windows

Nessus Plugin ID: 64687 ()

Bugtraq ID:


Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now