In memory fileless malwar edetection ..... any antimalware software?

Discussion in 'malware problems & news' started by aigle, Sep 10, 2015.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    This one definitely worth a read: https://www.symantec.com/content/dam/symantec/docs/security-center/white-papers/increased-use-of-powershell-in-attacks-16-en.pdf
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Will do some reading. BTW, this is a new tool that will disable a couple of things. Nothing special, but might come in handy:

    https://github.com/securitywithoutborders/hardentools
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    OK I see. But I was talking about apps that are trying to launch system tools, in EXE Radar this is called "vulnerable processes". So this hasn't got anything to do with blocking exploits. I believe it's only common for apps to launch rundll32 and regsvr32, and it's best to monitor these system tools with HIPS. And for example, if apps launch explorer or svchost, you should already know they might be trying to perform process hollowing.
     
  4. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Also quoted in the Symantec article is a Blackhat article about WMI malware I am posting here separately: https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor-wp.pdf

    Although it is very difficult to stop WMI based malware, it can be detected by use of Autoruns.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.