At Fortinet, we monitor suspicious executables that make use of open-source tools and frameworks. One of the things that we keep an eye out for is tools that use the Donut project. Donut is a position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters. During our daily threat-hunting process in early February, we encountered a kernel driver that used the Donut tool and caught our attention for further analysis.

The sample that triggered our rule was a driver called WinTapix.sys (which is why we named it WINTAPIX). Since it uses Donut, we decided to analyze it further. It turned out to be a very interesting sample that we believe is being used in targeted attacks against countries in the Middle East.


Hp Driver Download Middle East


Download Zip 🔥 https://tiurll.com/2y67od 🔥



This captured sample was compiled in May 2020 but was only uploaded to Virus Total in February of this year. Pivoting from this sample, we found another variant of this driver with the same name that was compiled around the same time, but it was uploaded to Virus Total in September 2022. Pivoting again from the used certificates, we found another variant of the WINTAPIX driver with the SRVNET2.SYS name. This sample was compiled in June 2021 and was first observed in the wild in December 2021.

Observed telemetry shows that 65% of the lookups for this driver were from Saudi Arabia, indicating it was a primary target. This same telemetry shows a considerable increase in the number of lookups for this driver in August and September 2022 and again in February and March 2023. This may indicate that the actor(s) behind this driver was operating major campaigns on these dates.

However, we still do not have enough information about how this driver has been distributed and who was behind these operations. Based on the victimology, we suspect an Iranian threat actor developed this driver. Observed telemetry shows that while this driver has primarily targeted Saudi Arabia, it has also been detected in Jordan, Qatar, and the United Arab Emirates, which are the classic targets of Iranian threat actors.

Since Iranian threat actors are known to exploit Exchange servers to deploy additional malware, it is also possible that this driver has been employed alongside Exchange attacks. To that point, the compilation time of the drivers is also aligned with times when Iranian threat actors were exploiting Exchange server vulnerabilities.

Its digital signature is invalid, meaning the threat actor might first need to load a vulnerable (but legitimate) driver and exploit that to load the Wintapix.sys. But once the driver is loaded, the following execution chain runs:

Interestingly, the driver is set to load in Safe Boot. Safe Boot, also known as Safe Mode, is a diagnostic startup mode in Windows that launches the system with minimal drivers and services. It is designed to help users troubleshoot and resolve software or driver-related issues that might prevent the system from starting normally. Loading the driver in Safe Boot also adds another layer of persistence to the mix.

This blog provided a detailed analysis of a driver named WinTapix, which we identified in early Feb of this year. The driver uses a Donut open-source payload to inject its shell code. It seems to be primarily targeting Saudi Arabia. The attribution process of this driver is still ongoing, but based on the victims, we assess with low confidence that this is a work of an Iranian threat actor.

FortiEDR natively detects and blocks the malicious executables identified in the report based on their behavior. The following image shows how FortiEDR detects the suspicious driver load and flags the driver as malicious.

This study chronicles the narratives of key stakeholders - the Arab states, the Islamic Republic of Iran, Israel, the Russian Federation, and the United States of America - who have been closely involved in Zone-related processes since 1974. By distilling insights from these narratives, the study uncovers major drivers and themes that underlie the behaviour of these stakeholders toward the Zone. Additionally, it provides a comprehensive historical account of important Zone-related processes and events from all of these perspectives.

The Israeli military has since unleashed a brutal bombing campaign on the Gaza Strip, killing at least 11,180 people, including 4,609 children. Hundreds of thousands of Gaza's residents have been displaced amid unrelenting bombardment and ground invasion by Israeli troops.

A key security measure to mitigate against malicious drivers is Driver Signature Enforcement, which ensures that only drivers signed by Microsoft can be loaded on the system. The tech giant also maintains driver block rules to protect against known vulnerable drivers.

"Since Iranian threat actors are known to exploit Exchange servers to deploy additional malware, it is also possible that this driver has been employed alongside Exchange attacks," the researchers said.

The development comes as the ALPHV (aka BlackCat or Noberus) ransomware group has been observed taking advantage of a malicious signed driver to impair security defenses and escape detection for extended periods of time.

POORTRY is the name assigned to a Windows kernel driver that comes with capabilities to terminate security software. Late last year, it was disclosed as used by ransomware gangs and a threat actor known as UNC3944 (aka Roasted 0ktapus and Scattered Spider).

The 2023 Formula Regional Middle East Championship was a multi-event, Formula Regional open-wheel single seater motor racing championship. The championship featured a mix of professional and amateur drivers, competing in Formula Regional cars. It was the inaugural season of the championship, using the venues and dates for what was originally planned to be the Formula Regional Asian Championship, with the Asian Championship then being relaunched in October of the same year.[1]

The season was held in January and February of 2023. Andrea Kimi Antonelli won the drivers' championship in the penultimate race, and in doing so also became rookie cup winner. His team, Mumbai Falcons Racing Limited, won the teams' title.

The first ever Formula Regional Middle East Championship began in the middle of January at Dubai Autodrome with Gabriele Min and Andrea Kimi Antonelli sharing poles in qualifying. Min kept his lead at the start of race one as Antonelli in second was overtaken by Dino Beganovic. The top pair fought for the lead all throughout the race, unbothered by two safety car interventions. A timing glitch meant the "last lap" message was shown one lap too early, and Min's team relayed that wrong information to him. He kept Beganovic behind as the pair crossed the line, but then slowed in anticipation of the race being over. This dropped him out of contention, promoting Matas Zagazeta to second. Third was Taylor Barnard, who had a remarkable race after starting in 27th. Race two was a much calmer affair, as Nikhil Bohra took a lights-to-flag victory starting from reverse-grid pole. Aiden Neate also finished where he started, in second, and Barnard was once again third, though this time he only had to climb five spots to do so. Antonelli was unable to hold on to his race three pole position, as Mari Boya went right past him on lap one. From then on, he built a gap to Antonelli and controlled the race. The race went ahead without interruptions, and Tasanapol Inthraphuvasak completed the podium. Antonelli's consistency allowed him to take the points lead by six points over Rafael Cmara.[25][26][27]

Just three days later, racing was back on in Kuwait, and qualifying was topped by the same two drivers. Race one began with the top three drivers, all Hyderabad Blackbirds, tripping over each other into the first braking zone. This meant Drksen lost his second pole and also allowed Antonelli through into second place, before he eventually got past Boya for the lead. He kept him behind until the Spaniard got overtaken by Cmara, and took his first win in the category. Debutant Kirill Smal started race two at the front and had to content with Dufek and Barnard, before the latter then got into the lead and built a gap. This was not to last, however, as his car then started breaking down and he fell down the order. Smal was back in the lead, but Antonelli, who had started tenth and steadily climbed up the order, made short work of his lead, overtook him and claimed another win. Smal then received a penalty, allowing Villagmez and Lorenzo Flux to pick up podiums. At the start of race three, Antonelli again picked up the lead, but the move was made off track, so he sped off to build a gap in anticipation of a penalty. That used up too much of his tires too soon, however, and by the end of the race he fell back into the clutches of Barnard, who overtook him to claim the win. The penalty still came for Antonelli, dropping him back behind Cmara and Flux. However, his double win meant he now had a 44-point lead over his nearest challenger Barnard.[31][32][33]

The championship was dominated by category rookies, who occupied the top three places in the final standings. Antonelli showed remarkable consistency, only finishing outside the top ten when the title was already all but secured. Being already handled as a generational talent after dominating the European F4 scene in 2022, his FRMEC campaign was the best possible preparation for the FRECA season. Barnard also quickly adapted to the car, often matching Antonelli, but his championship challenge was hampered by bad luck, like the disqualification in the first Dubai qualifying, or the mechanical failure in the penultimate Kuwait race. For the championship itself, the transition from the Asian to the Middle Eastern moniker went smoothly, and driver and team interest remained very high, with healthy, deep grids all throughout the season.

In 2022 all countries of the region will face added pressures from climate change and rising prices, against a backdrop of uneven economic growth. Extreme heat, sustained drought, and the risks of water and food shortages could add to the burdens of a state system that is already straining from multiple pressures. These drivers will further impact the interplay between governments and their people and broader regional stability. 17dc91bb1f

dj zylo album download

list of lakes in india pdf download

download back soft key

pipe wrench model free download

how can i download facebook videos for free