New Radamant Ransomware Kit

Discussion in 'malware problems & news' started by itman, Dec 20, 2015.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I already understand, you're probably using Bouncer, but that's what I like about EXE Radar, there is no need to monitor individual folders, if you're not on the white list, you can't run.

    OK I see, but that's another topic. I was talking about malware running from system folders, that's what I meant with "system space".
     
  3. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,072
    Location:
    Canada
    It's Jetico pfw. I like to monitor in the event it's a harmless and even necessary action.

    It's usually a temp directory, of course, but I've had to create some bizarre Path rules, for example...

    Code:
    C:\Users\Admin1\AppData\Local\Adobe\AIH.*\install_flash_player_ax.exe
    ... otherwise I'm spending too much time micro-managing legitimate installer actions. Lately I'm drifting away from this kind of nanny state control, opting instead to simply restore a clean working recent image if ever needed, which has always only been required due to something breaking rather than malware-induced. I'm now just sticking with simple whitelisted AppLocker Publisher and Path rules on Windows. Linux, nothing at all other than browser hardening via sandboxing and scripting control. I'm the only user with Linux but there are care-free family members using Windows so I need to exercise a bit more diligence, thus the AppLocker lockdown approach.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I don't get it, why did you need to add these folders? A HIPS or anti-exe will alert about apps no matter where they are launched from, except if it's a legitimate system file.
     
    Last edited: Dec 31, 2015
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,594
    Location:
    U.S.A.
    First, check the HIPS or anti-exec default rules for which folders it is monitoring and what is being monitored. Eset's HIPS for example will by default allow program startups anywhere.

    Actually, the most critical monitoring is where files can be created and by whom. If the file doesn't exist, it can't be executed.
     
  6. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,072
    Location:
    Canada
    So I wouldn't be bothered by future legitimate Flash installer attempts in these locations and elsewhere.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,606
    Location:
    The Netherlands
    I think I misunderstood, these folders are monitored for file creation, correct? Personally I don't see the need for it, because it's often too hard to know if file creation is legit or not. But if you do have the knowledge, then why not.
     
  8. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,072
    Location:
    Canada
    Yes, legitimate file creation. It's why I wrote rather specific Path rules, to significantly reduce the chances a rogue Flash installer could execute there. I chose Path rules in some cases because both Publisher and File hash rules were not feasible in these cases. File hash are a nuisance when the file is always changing due to regular updates, and Publisher signatures are not always attached to these update files. I like to allow Adobe to check and alert to available updates, then I manually launch them. I also had firewall rules allowing the updater to check only Flash remote IP addresses. Overkill, I know, so I no longer bother with these extreme measures.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.