TGViewer
vx-underground vx-underground @vxunderground · 52.2K subscribers
Post #7990 7.81K
MalwareBytes has an local database on the machine. It is a SQLite database. It contains settings for various properties such as licensing, malware identified, and known-good and known-bad lists. This is standard anti-malware stuff. The database with "ThankYouForChoosingMalwarebytes" is the less interesting database, as it mostly contains settings (this can still be abused though).

Regardless, MalwareBytes does a couple of things with this SQLite stuff

MalwareBytes establishes a kernel-mode minifilter (mbam.sys). They setup minifilter callback routines to handle events on the system for process creation, process loading, and registry modification (Image 1)

In other words, MalwareBytes is notified immediately when a process is created or an executable image is loaded. When a process is created or an executable image is loaded, MalwareBytes has special functionality to temporarily "pause" execution so it can review it.

However, this "pause" happens faster than you or I can blink. Computers are fast.

The mbam.sys creates an internal record of all processes running. When a new process is loaded it is added to this internal record. When a program is closed, it is removed from the record. It does this so it doesn't accidentally review or "pause" the same process twice.

When a program is added to this list, the kernel-mode component communicates with the user-mode component that then signals and connects to a local SQLite database. The SQLite database then does a lookup to determine if the process "paused" is known or unknown (Image 2)

However, it should be noted, Image 2 is not the important SQLite instance I am looking for. This is something else MalwareBytes uses (and communicates to with kernel-mode components). The point still stands.

If it is known, it communicates back to the kernel-mode component that is it known. If it known, and known to be malicious, MalwareBytes takes action on the program attempting to run and immediately stops execution. If it is known to be good, MalwareBytes marks it internally as "seen" and keeps it in it's internal record.

Image 3 is from the internal database they use. It's fairly large and is mostly settings. I still haven't find where the really nice, big, and important dataset they use is. It requires more poking and more sticks.
  • ❤‍🔥 60
  • ❤ 24
  • 👍 4
  • 🔥 3
  • 👏 2
  • 🥰 1
  • 😁 1
  • 😢 1
More from @vxunderground
  1. Sep 29, 2026FBI Director Kash Patel, and the FBI accounts on social media, been talking about ShinyHun…
  2. Sep 29, 2026Me explaining to younger family members that in the 80s, 90s, and 2000s, you couldn't be o…
  3. Sep 28, 2026I know I probably shouldn't be so rude about it, but for real bro, if you just say, "There…
  4. Sep 28, 2026I've got like a dozen or so people DMing me about more Steam goop (malware) but NO ONE has…
  5. Sep 28, 2026> be me > get dm > "Smelly, you said you accidentally executed an information stealer on y…
  6. Sep 25, 2026Write-up which is factually accurate and cool https://studiominus.nl/ppg-september-inciden…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →