Skip to content

Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon#221

Merged
josehelps merged 2 commits into
magicsword-io:mainfrom
mnznndr97:byovd-research
Mar 13, 2026
Merged

Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon#221
josehelps merged 2 commits into
magicsword-io:mainfrom
mnznndr97:byovd-research

Conversation

@mnznndr97
Copy link
Copy Markdown
Contributor

Added new versions for

  • IObitUnlocker, used by 64030dbd5a77510a00d33ea4e5d9f4d11643f77686b7100b5e98ffff1938bdf3 to terminate Defender
  • Zemana, used by 60483e8755a4d977de3c93189dfcd29bb9519d3813602797469751b0dad39fc7 to terminate Defender
  • TfSysMon, used by 6cc73c52156f1c7ecd36951aaeb146ce5e690afd62214c5e4bedb328e859d013 to terminate Defender

@TheMagicClaw
Copy link
Copy Markdown
Collaborator

Thank you @mnznndr97 for these valuable new samples! I've reviewed your PR and performed VirusTotal verification for the mentioned hashes:

  • IoBitUnlocker (SHA256): - Hash matches VirusTotal. Signature info was none.
  • Zemana (SHA256): - Hash matches VirusTotal. Signed by CleverSoar Electronic Technology Co., Ltd. via GlobalSign.
  • TfSysMon (SHA256): - Hash matches VirusTotal. Signed by Inno Setup.

The YAML structure appears consistent with other entries in the repository. Great work adding these!

@josehelps josehelps merged commit 900fd27 into magicsword-io:main Mar 13, 2026
josehelps added a commit that referenced this pull request Mar 13, 2026
Use .get() with safe defaults when accessing sample-level SHA1/SHA256
keys in gen_authentihash_lists and gen_loadsdespitehvci_lists. Samples
from PR #221 may not have all hash types, causing KeyError on generation.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants