Cybereason creates ‘vaccine’ to stop Remcos RAT

Discussion in 'malware problems & news' started by hawki, Aug 14, 2017.

  1. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    I have a better way. Just monitor cmd.exe execution.
     
  3. NormanF

    NormanF Registered Member

    Joined:
    Feb 20, 2009
    Posts:
    2,879
    SRP blocks execution from the named folders by default.
     
  4. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    That notorious Temp folder again. Just like in Windows 98 days.

    Secure Folders is another little lockdown for folders and ERP can monitor for the cmd.exe attempt.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.