Stealthy BLISTER malware slips in unnoticed on Windows systems

Discussion in 'malware problems & news' started by guest, Dec 23, 2021.

  1. guest

    guest Guest

    December 23, 2021
    Elastic Security: Elastic Security uncovers BLISTER malware campaign
     
  2. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    417
    Location:
    Finland
    Maybe SecureAplus and its Name & Thumbprint Certificated check block this in a first place?
     
  3. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,314
    maybe, but thats no longer an issue
    they need a new cert and ofc they will have. maybe they will change it again before next detection. checking the cert may help, but better is to prevent its intrusion and its behavior as shown
    you need to lock or sandbox such calls. the rest see likend article.
     
  4. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    417
    Location:
    Finland
    If they need a new cert, does it pass SAP Essentials Name and Thumbprint check, i doubt that. So then it can't do anything.
    In SAP+ there's already a default rule for rundll, tho its like "always block if rundll runs javacript". Quite good for a basic rule. Sure tech savvys can make their own rules.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    I guess it's this type of malware that can often bypass multiple AV's, they are using quite nifty tricks. Cool that Elastic was able to detect this, but they didn't perform too good in the latest AV-Comparatives Business Security Test. Would be interesting to know if a tool like OSArmor could have blocked this malware post execution.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.