Improved scripts in .lnk files now deliver Kovter in addition to Locky

Discussion in 'malware problems & news' started by ronjor, Feb 3, 2017.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,163
    Location:
    Texas
    msft-mmpcmsft-mmpcFebruary 2, 2017
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    The recommended Microsoft mitigation:

    In Windows 10, lock down PowerShell version 5 to “Constrained Mode“, which limits the extended language features that can lead to unverifiable code execution such as direct .NET scripting, invocation of Win32 APIs via the Add-Type cmdlet, and interaction with COM objects.
    More on that:

    In version 5, PowerShell now reduces its functionality to “Constrained Mode” for both interactive input and user-authored scripts when it detects that PowerShell scripts have an ‘Allow Mode’ policy applied to them. Constrained PowerShell limits the language mode to Constrained Language (as described in about_Language_Modes), a mode first introduced for Windows RT.

    Ref.: https://blogs.msdn.microsoft.com/powershell/2015/06/09/powershell-the-blue-team/
    The problem is this mitigation is only available in AppLocker. Thanks for nothing Microsoft.

     
  3. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    I think Appguard covers this.
     
  4. Lockdown

    Lockdown Registered Member

    Joined:
    Oct 28, 2016
    Posts:
    772
    Location:
    Wilders Security
    AppGuard already protects against cmd and powershell abuse.

    Also add both wscript.exe and cscript.exe to Guarded Apps list or disable them by adding to User Space (YES).
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Powershell mode set to Constrained Mode in Win 10 Home.

    Verified below:

    Powershell_Mode.png
     
  6. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    Lckdown

    My setup has all along been to uncheck Powershell in guarded apps but for some reason I can't remember why now , I had also added then to user space and YES.
    Then I have most of my security programs added as Power Applications.
     

    Attached Files:

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.