- Apr 13, 2013
- 3,224
Although this prelude video just showed the gross effects (that which can be seen via TaskManager), the one later today will show the cascade of processes that results in the final infection. But with regard to AV detection, even though this guy has been out for 2 weeks, for something that has been around for so long the detection rate (like 21) is relatively small and are mostly dumb (via definitions) detection. I was actually surprised that none of the 2nd opinion scanners picked up on the rtf when it was just hanging out on the Desktop.
But the AV detection's of the initial rtf file are still a high point for the traditional AV- of the spawned txt and ps1 files that will actually do the damage the AV detection is horrendous (to be fair, Symantec and Mcafee were the only vendors to stop the cascade by detection of one of the spawn). As to blocking cmd.exe from running, a more elegant and viable solution would have been to block the initial spawn, jl.txt.
A popular stand on stuff like this is: "You gotta shut off wscript" and/or "Disable PowerShell!!!!". By extension, this is like saying "Never Turn On your computer!!!!". Whenever I see drivel like that it reminds me of the old joke:
Man walks in to the Doctors office and says: "Doctor, Doctor- my arm hurts when I do this!"
Doctor says "Well, then don't do that".
I would think that Geeks Like Us should demand a better solution.
But the AV detection's of the initial rtf file are still a high point for the traditional AV- of the spawned txt and ps1 files that will actually do the damage the AV detection is horrendous (to be fair, Symantec and Mcafee were the only vendors to stop the cascade by detection of one of the spawn). As to blocking cmd.exe from running, a more elegant and viable solution would have been to block the initial spawn, jl.txt.
A popular stand on stuff like this is: "You gotta shut off wscript" and/or "Disable PowerShell!!!!". By extension, this is like saying "Never Turn On your computer!!!!". Whenever I see drivel like that it reminds me of the old joke:
Man walks in to the Doctors office and says: "Doctor, Doctor- my arm hurts when I do this!"
Doctor says "Well, then don't do that".
I would think that Geeks Like Us should demand a better solution.