I'm going down the list, and I see 100%, 100%, 100%...
Impressive! You don't do macOS, do you?
Incompatible developer I believe.
I'm going down the list, and I see 100%, 100%, 100%...
Impressive! You don't do macOS, do you?
OSArmor is not intended to block signed EXE files. It can block them when they are run from suspicious locations. It can also block some LOLBins, etc.OSArmor on all systems here. I have a question though. So if this malware was signed, that's one protection the malware can bypass. However, how did it get past the rest? I mean, does anyone know the specific mechanism of this malware. I haven't ever used the Custom Block-Rules dialog, but maybe this could be useful for preventing this kind of attack?
OSA lets you make custom block rules, if you want, but it's easier to just use a program that is specifically designed for that, such as NVT EXE Radar Pro or Hard_Configurator.signed EXE files are allowed by design to run from Desktop
Technically, the last sample did not bypass OSArmor, because signed EXE files are allowed by design to run from Desktop.
Technically, the last sample did not bypass OSArmor, because signed EXE files are allowed by design to run from Desktop.
I wonder why people don't seem to use NVT ERP very much anymore?