HitmanPro.Alert 3 build 180 Final released

Status
Not open for further replies.

Welldone

Level 5
Thread author
Verified
Dec 29, 2012
235
Since the four Community Technical Previews of HitmanPro.Alert 3 last year, our customers and the security community showed strong interest. Enhanced with the valuable feedback that we received, we are excited to announce the general availability (GA) of HitmanPro.Alert 3 – build 180.

HitmanPro.Alert version 3 introduces Exploit Mitigations, of which its hardware-assisted Control-Flow Integrity (CFI) technology is perhaps its most striking feature. CFI is a technique to prevent flow of control not intended by the original application, without requiring the source code or debug symbols of the protected application. With CFI, HitmanPro.Alert 3 effectively stops attackers that hijack control-flow to combine short pieces of benign code, already present in a system, for a malicious purpose; a so-called return-oriented programming (ROP) attack. This capability is achieved by programming and leveraging a hardware feature in modern Intel® processors to track code execution and assist in the detection of attacks in real-time – an industry-first method not found in any other security product.

Besides a performance advantage, employing hardware traced records has a security benefit over software stack-based approaches. Stack-based solutions, like Microsoft EMET, rely on stack data, which is (especially in case of a ROP attack) in control of the attacker, who in turn can affect or control the defender as well.

Cybercriminals and hackers are becoming increasingly more proficient in finding and attacking previously unknown vulnerabilities to bypass antivirus software as well as memory protections (DEP+ASLR) to silently infiltrate computers. Well known cases that led to the discovery of zero-day attacks, like Operation SnowMan, GreedyWonk and Clandestine Fox (uncovered by security firm FireEye) as well as the recent Adobe Flash Player exploits, show that attackers are adept in creating malware (shellcode) by borrowing instructions from legitimate applications running on the victim computer – a ROP attack. Antivirus software is not designed to block this as a ROP attack does not require malicious files or processes. HitmanPro.Alert version 3 is built to stop existing and future attacks whether they are conducted by exploit kits or (foreign) nation-state hackers, without requiring prior knowledge of attacks or abused vulnerabilities.

Besides Exploit Mitigations, HitmanPro.Alert 3 also offers Man-in-the-Browser Intruder Detection (Safe Browsing), Cryptolocker Protection (CryptoGuard), System Vaccination, Webcam Notifier, Keystroke Encryption, BadUSB Protection and our Forensics-based Anti-Malware.

Screenshot
alert3_png_247643.png


Review
We asked Malware Research Group (MRG Effitas) to test and write an independent review on HitmanPro.Alert 3. In addition we sponsored their Real World Exploit Prevention Test comparison wherein they threw a very diverse set of in-the-wild exploits (12 different exploit kits) and attacks on 16 different vulnerabilities, against 13 different products.

Second part of the comparison revolved around an artificial zero-day exploit attack. The purpose of this attack is to provide a more realistic picture of the capabilities of security software against real zero-day attacks. Just like real-world exploit attacks, this attack has not yet been discovered by security researchers and is unknown to blacklist-based technologies that rely on prior discovery, like URL filtering and virus signatures (which is a good indication why all security solutions, other than Microsoft EMET and Malwarebytes Anti-Exploit, failed te detect this attack).
We also provided MRG with an advanced ROP chain and shellcode for their artificial zero-day attack, which is able to bypass every popular anti-exploit solution.

The techniques that we used to defeat these solutions are not new and available in the public domain for a long time. The purpose of our attack is to show readers that any motivated attacker is able to (re-)weaponize exploits to bypass security solutions. In effect it also shows the power of our unique hardware-assisted exploit protection technology. We provided all the details surrounding our attack as well. They are made available by MRG Effitas for verification by interested researchers.

You can download the report (which includes the review, comparison and the artificial zero-day attack) from this link: https://www.mrg-effitas.com/mrg-effitas-real-world-exploit-prevention-test-march-2015/

Release notes build 180 GA (changelog compared to build 155 RC)
  • Improved Lockdown mitigation to enforce safe execution of VBScript. This mitigates the exploitation technique known as "VBScript God Mode".
  • Improved Load Library mitigation to detect shellcode.
  • Improved Load Library mitigation to detect reflective loaded libraries.
  • Improved branch-based hardware-assisted ROP mitigation (part of Control-Flow Integrity).
  • Improved software-based ROP mitigation (part of Control-Flow Integrity).
  • Improved IAT Filtering.
  • Improved Dynamic Heap Spray mitigation.
  • Improved CryptoGuard mitigation, specifically protection of connected network drives.
  • Improved BadUSB mitigation.
  • Improved Enforce DEP mitigation.
  • Improved Safe Browsing intruder alert, which now also shows the correct technical details.
  • Improved Software Radar.
  • Improved compatibility with EMET 5.1.
  • Improved compatibility with Sandboxie 4.16.
  • Fixed upgrade from HitmanPro.Alert version 2 to version 3. In previous builds, the upgrade could affect the functionality of the existing connected keyboard.
Changelog compared to build 179 RC
  • Improved HeapSpray mitigation.
  • Improved network driver compatibility.
Remarks
  • HitmanPro.Alert 3 allows experienced computer users to apply exploit mitigations to applications of their own choosing. But the following software types should not be protected by HitmanPro.Alert:
    • Anti-malware and intrusion prevention or detection software
    • Debuggers
    • Software that handles digital rights management (DRM) technologies (i.e. videogames)
    • Software that use anti-debugging, obfuscation, or hooking technologies
  • HitmanPro.Alert 3 is not compatible with the Microsoft Enhanced Mitigation Experience Toolkit (EMET) version 5.2. As workaround you can disable EAF and EAF+ in EMET 5.2. HitmanPro.Alert is fully compatible with EMET 4.1 and EMET 5.1.
Source: Post#4898

Homepage:
http://www.surfright.nl/en/alert

Download link:
http://dl.surfright.nl/hmpalert3.exe

Getting Started Manual: http://dl.surfright.nl/HitmanPro Alert Getting Started.pdf
 

Janl92l

Level 7
Verified
Nov 7, 2014
339
i not see any prices on the site downloaded it and its 29 Days trial. Hmm,bad i cant afford to buy it at the moment. Realy nice extra layer of protection along our existing antivirus. Anyway,needed to uninstall cant buy a license atm but thanks for the post. :)
 
Y

yigido

thank you for the information :)
I would like to ask, what free version offers to end-users after trial?

Thank you.
 

Welldone

Level 5
Thread author
Verified
Dec 29, 2012
235
i not see any prices on the site downloaded it and its 29 Days trial. Hmm,bad i cant afford to buy it at the moment. Realy nice extra layer of protection along our existing antivirus. Anyway,needed to uninstall cant buy a license atm but thanks for the post. :)

shop.jpg


To enable all protection capabilities of HitmanPro.Alert, a license is required. During initial setup, home users are granted a free HitmanPro trial license, which is valid for 30 days and enables all features. This license is identical to the one used for our on-demand second opinion HitmanPro Anti-Malware tool.

If the computer already enjoyed a free but expired HitmanPro license, a free trial for HitmanPro.Alert is not available.
Commercial (paid) licenses can be purchased online: http://www.hitmanpro.com/shop

After purchasing a license, you will receive an e-mail with a personal product key that you must enter and activate in HitmanPro.Alert.
 
Last edited:
  • Like
Reactions: Janl92l

Erik Loman

From SurfRight
Verified
Developer
Jan 27, 2015
61
If the license expires, HitmanPro.Alert drops into Free mode. This means that CryptoGuard and Exploit Mitigations are disabled, BUT Safe Browsing (detects browser intruders like banking malware), Webcam Notifier, Keystroke Encryption and Anti-BadUSB are still enabled.
 

Welldone

Level 5
Thread author
Verified
Dec 29, 2012
235
HitmanPro.Alert 3 build 181

A minor update.

Changelog
  • Improved Shellcode mitigation
  • Improved keystroke encryption on applications in the Other category
  • Fixed keystroke encryption was no longer working when service was manually restarted.
  • Changed default flyout to once per logon session
  • Changed default live keystroke encryption in colored window border to off
Existing users are automatically updated.

Note: The changed defaults only apply to fresh installs. Upgraded installations keep the previous default setting to avoid confusion.

Download link: http://dl.surfright.nl/hmpalert3.exe
 
Last edited:

Tony Cole

Level 27
Verified
May 11, 2014
1,639
Just updated to 181 now at the bottom of the browser where the green boarder shows it no longer shows (when typing) the different letters for keyloggers?
 

Erik Loman

From SurfRight
Verified
Developer
Jan 27, 2015
61
Just updated to 181 now at the bottom of the browser where the green boarder shows it no longer shows (when typing) the different letters for keyloggers?
Read changelog. You can enable the feature via the Safety notifier area in the main GUI.
 

Welldone

Level 5
Thread author
Verified
Dec 29, 2012
235
HitmanPro.Alert 3 build 182 BETA

Changelog
  • Improved DEP mitigation
  • Improved HeapSpray mitigation
  • Improved Control-Flow Integrity mitigation
  • Improved Lockdown mitigation
  • Improved Shellcode mitigation
  • Improved compatibility with RapidMiner
  • Improved compatibility with Kaltura
  • Fixed false positive on streaming sites using Silverlight; eg. Netflix.com and itvonline.nl
  • Fixed apostrophe and quote character encryption in Internet Explorer on Windows 7
  • Fixed right-click properties alert in Internet Explorer
  • Fixed flyout not appearing when an update is pending
Download
http://test.hitmanpro.com/hmpalert3b182.exe

You can install this version via upgrade (just run this executable).
 

Welldone

Level 5
Thread author
Verified
Dec 29, 2012
235
HitmanPro.Alert 3.0.38 Build 183 (2015-04-17)

Changelog
  • Improved DEP mitigation.
  • Improved HeapSpray mitigation.
  • Improved Control-Flow Integrity mitigation.
  • Improved Lockdown mitigation.
  • Improved Shellcode mitigation.
  • Improved compatibility with RapidMiner.
  • Improved compatibility with Kaltura.
  • Fixed false positive on streaming sites using Silverlight; eg. Netflix.com and itvonline.nl.
  • Fixed apostrophe and quote character encryption in Internet Explorer on Windows 7.
  • Fixed right-click properties alert in Internet Explorer.
  • Fixed flyout not appearing when an update is pending.
Download
http://dl.surfright.nl/hmpalert3.exe
 

soccer97

Level 11
Verified
May 22, 2014
517
Is anyone else having problems with the latest build? (3.0.38 build 183)? I had to disable Safe browsing for Firefox and Google Chrome (didn't try IE 11) because the latest version of Adobe Flash Player kept crashing on every webpage. I also had to disable the following in Exploit Mitigtations for Adobe Flash Player v. 17.0.0.169 (Application Lockdown, Mandatory ASLR, Bottom up ASLR). Now it works. IE 11 is also crashing whenever I open it and browse to a website all of the sudden. These problems occured after uninstalling HitmanPro.Alert build 181, rebooting and then installing build 183.Now running w/ Safe Browsing off and whenever I need IE 11, Exploit Mitigation off. PowerPoint 2013 keeps crashing all of the sudden also. They all happened around the same time.

IE Crash
Problem Event Name: APPCRASH
Application Name: IEXPLORE.EXE
Application Version: 11.0.9600.17728
Problem: StackHash (with memory address)



I can provide the WER report via PM if needed.
 

Erik Loman

From SurfRight
Verified
Developer
Jan 27, 2015
61
Is anyone else having problems with the latest build? (3.0.38 build 183)? I had to disable Safe browsing for Firefox and Google Chrome (didn't try IE 11) because the latest version of Adobe Flash Player kept crashing on every webpage. I also had to disable the following in Exploit Mitigtations for Adobe Flash Player v. 17.0.0.169 (Application Lockdown, Mandatory ASLR, Bottom up ASLR). Now it works. IE 11 is also crashing whenever I open it and browse to a website all of the sudden. These problems occured after uninstalling HitmanPro.Alert build 181, rebooting and then installing build 183.Now running w/ Safe Browsing off and whenever I need IE 11, Exploit Mitigation off. PowerPoint 2013 keeps crashing all of the sudden also. They all happened around the same time.

IE Crash
Problem Event Name: APPCRASH
Application Name: IEXPLORE.EXE
Application Version: 11.0.9600.17728
Problem: StackHash (with memory address)



I can provide the WER report via PM if needed.
Thank you for reporting. Send me the WER report via PM.

What security products are you using?
 

Welldone

Level 5
Thread author
Verified
Dec 29, 2012
235
HitmanPro.Alert 3 Build 184 BETA

This build adds a new feature where the user can add applications that are to be excluded. For example, you can add GTAV or other games that do not like injections.

exclusion_png_247975.png


Changelog
  • Added application exclusion to "Your applications" panel (scroll to the far right)
  • Fixed a random crash in the service (may be cause of keyboard encryption failure)
  • Several minor improvements
Download
http://test.hitmanpro.com/hmpalert3b184.exe

Source: Post #5496
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top