Serious Discussion Can Anti-Viruses stop RATS that have their connection established?

Trident

Level 28
Verified
Top Poster
Well-known
Feb 7, 2023
1,739
Just don't store passwords in browsers. Store them in your PW manager............a good one. And if you use a weak PW manager.........then you had it
Cool but StealC (Vidar knock-off) can exfiltrate the following:

Annex​

Annex 1 – Stealc capabilities​

Targeted web browsers​

Web browserPath of targeted fileFormat
Google Chrome\Google\Chrome\User Datachrome
Google Chrome Canary\Google\Chrome SxS\User Datachrome
Chromium\Chromium\User Datachrome
Amigo\Amigo\User Datachrome
Torch\Torch\User Datachrome
Vivaldi\Vivaldi\User Datachrome
Comodo Dragon\Comodo\Dragon\User Datachrome
EpicPrivacyBrowser\Epic Privacy Browser\User Datachrome
CocCoc\CocCoc\Browser\User Datachrome
Brave\BraveSoftware\Brave-Browser\User Datachrome
Cent Browser\CentBrowser\User Datachrome
7Star\7Star\7Star\User Datachrome
Chedot Browser\Chedot\User Datachrome
Microsoft Edge\Microsoft\Edge\User Datachrome
360 Browser\360Browser\Browser\User Datachrome
QQBrowser\Tencent\QQBrowser\User Datachrome
CryptoTab\CryptoTab Browser\User Datachrome
Opera Stable\Opera Softwareopera
Opera GX Stable\Opera Softwareopera
Mozilla Firefox\Mozilla\Firefox\Profilesfirefox
Pale Moon\Moonchild Productions\Pale Moon\Profilesfirefox
Opera Crypto Stable\Opera Softwareopera

Targeted browser extensions​

Cryptocurrency walletExtension ID
MetaMaskdjclckkglechooblngghdinmeemkbgci
MetaMaskejbalbakoplchlghecdalmeeeajnimhm
MetaMasknkbihfbeogaeaoehlefnkodbefgpgknn
TronLinkibnejdfjmmkpcnlpebklmnkoeoihofec
Binance Walletfhbohimaelbohpjbbldcngcnapndodjp
Yoroiffnbelfdoeiohenkjibnmadjiehjhajb
Coinbase Wallet extensionhnfanknocfeofbddgcijnmhnfnkdnaad
Guardahpglfhgfnhbgpjdenjgmdgoeiappafln
Jaxx Libertycjelfplplebdjjenllpjcblmjkfcffne
iWalletkncchdigobghenbbaddojjnnaogfppfj
MEW CXnlbmnnijcnlegkjjpcfjclmcfggfefdm
GuildWalletnanjmdknhkinifnkgdcggcfnhdaammmj
Ronin Walletfnjhmkhhmkbjkkabndcnnogagogbneec
NeoLinecphhlgmgameodnhkjdmkpanlelnlohao
CLV Walletnhnkbkgjikgcigadomkphalanndcapjk
Liquality Walletkpfopkelmapcoipemfendmdcghnegimn
Terra Station Walletaiifbnbfobpmeekipheeijimdpnlpgpp
Keplrdmkamcknogkgcdfhhbddcghachkejeap
Solletfhmfendgdocmcbmfikdcogofphimnkno
Auro Wallet(Mina Protocol)cnmamaachppnkjgnildpdmkaakejnhae
Polymesh Walletjojhfeoedkpkglbfimdfabpdfjaoolaf
ICONexflpiciilemghbmfalicajoolhkkenfel
Coin98 Walletaeachknmefphepccionboohckonoeemg
EVER Walletcgeeodpfagjceefieflmdfphplkenlfk
KardiaChain Walletpdadjkfkgcafgbceimcpbkalnfnepbnk
Rabbyacmacodkjbdgmoleebolmdjonilkdbch
Phantombfnaelmomeimhlpmgjnjophhpkkoljpa
Brave Walletodbfpeeihdkbihmopkbjmoonfanlbfcl
Oxygenfhilaheimglignddkjgofkcbgekhenbh
Pali Walletmgffkfbidihjpoaomajlbgchddlicgpn
BOLT Xaodkkagnadcbobfpggfnjeongemjbjca
XDEFI Wallethmeobnfnfcmdkdcmlblgagmfpfboieaf
Namilpfcbjknijpeeillifnkikgncikgfhdo
Maiar DeFi Walletdngmlblcodfobpdpecaadgfbcggfjfnm
Keeper Walletlpilbniiabackdjcionkobglmddfbcjo
Solflare Walletbhhhlbepdkbapadjdnnojkbgioiodbic
Cyano Walletdkdedlpgdmmkkfjabffeganieamfklkm
KHChcflpincpppdclinealmandijcmnkbgn
TezBoxmnfifefkajgofkcjkemidiaecocnkjeh
Templeookjlbkiijinhpmnjffcofjonbfbgaoc
Gobyjnkelfanjkeadonecabehalmbgpfodjm
Ronin Walletkjmoohlgokccodicjjfebfomlbljgfhk
Byonenlgbhdfgdhgbiamfdfmbikcdghidoadd
OneKeyjnmbobjmhlngoefaiojfljckilhhlhcj
DAppPlaylodccjjbdhfakaekdiahmedfbieldgik
SteemKeychainjhgnbkkipaallpehbohjmkbjofjdmeid
Braavos Walletjnlgamecbpmbajjfhmmmlhejkemejdma
Enkryptkkpllkodjeloidieedojogacfhpaihoh
OKX Walletmcohilncbfahbmgdjkbpemcciiolgcge
Sender Walletepapihdplajcdnnkdeiahlgigofloibg
Hashpackgjagmgiddbbciopjhllkdnddhcglnemk
Eternlkmhcihpebfmpgmihbkipmjlmmioameka
Pontem Aptos Walletphkbamefinggmakgklpkljjmgibohnba
Petra Aptos Walletejjladinnckdgjemekebdpeokbikhfci
Martian Aptos Walletefbglgofoippbgcjepnhiblaibcnclgk
Finniecjmkndjhnagcfbpiemnkdpomccnjblmj
Leap Terra Walletaijcbedoijmgnlmjeegjaglmepbmpkpi
Trezor Password Managerimloifkgjagghnncjkhggdhalmcnfklk
Authenticatorbhghoamapcdpbohphigoooaddinpkbai
Authygaedmjdfmmahhbjefcbgaolhhanlaolb
EOS Authenticatoroeljdldpnmdbchonielidgobddffflal
GAuth Authenticatorilgcnhelpchnceeipipijaljkblbcobl
Bitwardennngceckbapebfimnlniiiahkandclblb
KeePassXCoboonakemofpalcgghocfoadofidjkkk
Dashlanefdjamakpfbbddfjaooikfcpapjohcfmg
NordPassfooolghllnmhmmndgjiamiiodkpenpbb
Keeperbfogiafebfohielmmehodmfbbebbbpei
RoboFormpnlccmojcmeohlpggmfnbbiapkmbliob
LastPasshdokiejnpimakedhajhdlcegeplioahd
BrowserPassnaepdomgkenhinolocfifgehidddafch
MYKIbmikpgodpkclnkgmnpphehdgcimmided
Splikityjhfjfclepacoldmjmkmdlmganfaalklb
CommonKeychgfefjpcobfbnpmiokfjjaglahmnded
Zoho Vaultigkpcodhieompeloncfnbekccinhapdb
Opera Walletgojhcdgcpbpfigcaejpfhfegekdgiblk

Targeted desktop cryptocurrency wallets​

Cryptocurrency walletPath of targeted directoryFile
Bitcoin Core\Bitcoin\wallets\wallet.dat
Bitcoin Core Old\Bitcoin\wallet.dat
Dogecoin\Dogecoin\wallet.dat
Raven Core\Raven\wallet.dat
Daedalus Mainnet\Daedalus Mainnet\wallets\she*.sqlite
Blockstream Green\Blockstream\Green\wallets\.
Wasabi Wallet\WalletWasabi\Client\Wallets\.json
Ethereum\Ethereum\keystore
Electrum\Electrum\wallets\.
ElectrumLTC\Electrum-LTC\wallets\.
Exodus\Exodus\exodus.conf.json
Exodus\Exodus\window-state.json
Exodus\Exodus\exodus.wallet\passphrase.json
Exodus\Exodus\exodus.wallet\seed.seco
Exodus\Exodus\exodus.wallet\info.seco
Electron Cash\ElectronCash\wallets\.
MultiDoge\MultiDoge\multidoge.wallet
Jaxx Desktop (old)\jaxx\Local Storage\file__0.localstorage
Jaxx Desktop\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\.
Atomic\atomic\Local Storage\leveldb\.
Binance\Binance\app-store.json
Binance\Binance\simple-storage.json
Binance\Binance\.finger-print.fp
Coinomi\Coinomi\Coinomi\wallets\.wallet
Coinomi\Coinomi\Coinomi\wallets\
 

Brahman

Level 17
Verified
Top Poster
Well-known
Aug 22, 2013
827
I use Kaspersky which has HIPS, a Firewall, and also is a good anti-virus. Is that a secure setup?
As i said its multiple layers and I wouldn't say your setup is not enough, its more than enough for anyone with non risky habits, but if you wish you can add more like encrypted dns, a filtering Doh on router , a good router with good firewall Etc.
 

Xeno1234

Level 14
Thread author
Jun 12, 2023
699
As i said its multiple layers and I wouldn't say your setup is not enough, its more than enough for anyone with non risky habits, but if you wish you can add more like encrypted dns, a filtering Doh on router , a good router with good firewall Etc.
I mean the only risky thing I do is download game mods for minecraft thats it tbh
 
F

ForgottenSeer 97327

NEVER rely on an antivirus solution!
If Kaspersky and Harmony fail and Norton succeeds, will you install Norton?
Ditto if F-Secure succeeds?
You've got to stop believing that antivirus solutions are superheroes who will protect you from everything. They're not...

For a RAT, you already need to know whether the code is known. Some AVs like Eset or Kaspersky decompile the code. If they see a known piece of code, it will be blocked.
For Kaspersky, if the RAT tries to touch the system, it will also be blocked.
And if it gets past Kaspersky, the server's ip address or url must not be known....

Once again, most antivirus programs can protect you from it, some will do better, but if you don't download files like "FortniteVbuksFreeCracked.exe" or "MyDogIsBeautiful.jpg.jar" you risk nothing.
Smart Application Control (SAC) for FortniteVbuksFreeCracked.exe and SimpleWindopwsHardening (SWH) for MyDogIsBeautiful.jpg.jar would be a great and hassle free combo when your are on Windows11. Most RAT's are delivered through scriptors or weaponized documents which SWH provides excellent protection against. SAC adds a cloud based whitelist to any executable based intrusion (often the second stage in RAT attacks).

When you want to combine SAC+SWH with AVAST free you can also use Hard_Configurator (H_C) which has a special AVAST_hardened mode profile. The advantage of H_C with AVAST profile over SWH is that H_C allows you to block most common scriptors as extra protection: Setup Idea - Double cloud based whitelist protection for FREE Avast free also has a behavioral blocker and firewall which are additional protections against RAT intrusion as @Kongo explained).

With any other third-party AV I would combine SAC with SWH. The combo SAC + SWH is a simple and excellent addition to any AntiVirus solution to minimize the attack surface. On MT the number of people promoting SAC + SWH are low, while in my opinion it is a rock solid addition to your AV of choice. It is hassle free no-brainer addition to any third-pary AntiVirus for most users.
 
Last edited by a moderator:

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,612
Smart Application Control (SAC) for FortniteVbuksFreeCracked.exe and SimpleWindopwsHardening (SWH) for MyDogIsBeautiful.jpg.jar would be a great and hassle free combo when your are on Windows11. Most RAT's are delivered through scriptors or weaponized documents which SWH provides excellent protection against. SAC adds a cloud based whitelist to any executable based intrusion (often the second stage in RAT attacks).

When you want to combine SAC+SWH with AVAST free you can also use Hard_Configurator (H_C) which has a special AVAST_hardened mode profile. The advantage of H_C with AVAST profile over SWH is that H_C allows you to block most common scriptors as extra protection: Setup Idea - Double cloud based whitelist protection for FREE Avast free also has a behavioral blocker and firewall which are additional protections against RAT intrusion as @Kongo explained).

With any other third-party AV I would combine SAC with SWH. The combo SAC + SWH is a simple and excellent addition to any AntiVirus solution to minimize the attack surface. On MT the number of people promoting SAC + SWH are low, while in my opinion it is a rock solid addition to your AV of choice. It is hassle free no-brainer addition to any third-pary AntiVirus for most users.
I like your idea and SWH is a great tool, highly recommended for hardening Windows (y)
But I'm not sure if SAC is the ideal companion for all 3rd party antivirus:
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,612
SWH = Simple Windows Hardening:
SAC is Windows 11 only
 

Xeno1234

Level 14
Thread author
Jun 12, 2023
699
SWH = Simple Windows Hardening:
SAC is Windows 11 only
Ahh. Should I go to windows 11?
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,612
Ahh. Should I go to windows 11?
Not sure, does your current hardware support Windows 11?
I really like Windows 11, but others do not.
So, you must decide that for yourself.
There is no real need when Windows 10 is still in support till October 14, 2025.
 
Last edited:

Xeno1234

Level 14
Thread author
Jun 12, 2023
699
Not sure, does your current hardware support Windows 11?
I really like Windows 11, but others do not.
So, you must decide that for yourself.
There is no real need when Windows 10 is still in support till October 14, 2025.
I really like how it looks, I just dont like that I cant move the taskbar to the top of the screen, but thats something that really only I like lol
 
  • Like
Reactions: Jonny Quest

Xeno1234

Level 14
Thread author
Jun 12, 2023
699
SWH = Simple Windows Hardening:
Just to be sure, this should work with Kaspersky/Harmony, right?
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,612
Just to be sure, this should work with Kaspersky/Harmony, right?
Yes, for Kaspersky, not sure about Harmony.
Don't know enough about Harmony.
From the Simple Windows Hardening GitHub page:
Software incompatibilities

Windows built-in SRP cannot work with AppLocker (introduced via GPO or MDM WMI Bridge). In such a case, SimpleWindowsHardening shows an alert. Furthermore, the options related to SRP are Switched OFF and removed from the Settings menu.

From the year 2022, AppLocker (GPO) policies can work on Windows 10/11 Home and Pro. AppLocker is activated by default on Windows 11 ver. 22H2 or later (also on Windows Home), so SRP is disabled in the default configuration.

SimpleWindowsHardening ver. 2.1.1.1 can enable SRP on Windows 11, and SRP can also work with enabled Smart App Control (SAC).

Windows built-in SRP is incompatible with Child Account activated on Windows 10+ via Microsoft Family Safety. Child Account adds some AppLocker rules (via MDM), so SRP cannot work. Unfortunately, after removing Child Account, the AppLocker Policy files are not removed (unpleasant bug)! These policy files have to be removed manually to recover the SRP functionality.

SimpleWindowsHardening settings are not compatible with SRP introduced via Group Policies Object (GPO) available in Windows Pro, Education, and Enterprise editions. The GPO refresh feature will overwrite the SimpleWindowsHardening settings. So, before installing SimpleWindowsHardening, SRP has to be removed from GPO.

SimpleWindowsHardening will also conflict with any software which uses SRP, but such applications are rare (CryptoPrevent, SBGuard, AskAdmin, Ultra Virus Killer). Before installing SimpleWindowsHardening it will be necessary to uninstall the conflicting application.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,509

Xeno1234

Level 14
Thread author
Jun 12, 2023
699
Probably not really needed with Harmony. If I understood correctly, you can also set up script restrictions just like with Deep Instinct.
The Kaspersky Anti-Malware engine provides very good script coverage, therefore the restrictions may not be needed either.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top