Advice Request Symantec Endpoint Protection bypassed with a DLL (PoC)

Please provide comments and solutions that are helpful to the author of this topic.

Andrew3000

Level 11
Thread author
Verified
Top Poster
Malware Hunter
Well-known
Feb 8, 2016
516
"Symantec Endpoint Protection is bypassed super easily using my dusty DLL refresh PoC. After refreshing in-mem DLLs with the on-disk orig versions, userland hooks got removed completely, making the EDR blind, and allowing us to execute Meterpreter shellcode by simple API calls."
FAvYgUiXMAApi3s

Author:
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,127
Quite surprising, because Symantec sells itself as blocking everything and having a very good anti-attack :D

In the home environment, this attack will be prevented by Norton Download Insight (DLL or another kind of malware originated from the Internet or USB drive).
The attack can be dangerous in the Enterprises if the local network has been already hacked.
 

Vitali Ortzi

Level 22
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
In the home environment, this attack will be prevented by Norton Download Insight (DLL or another kind of malware originated from the Internet or USB drive).
The attack can be dangerous in the Enterprises if the local network has been already hacked.
Probably will get a reputation block but still it can affect home users in a script to bypass insight but it will probably not happen so don’t worry
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,127
Probably will get a reputation block but still it can affect home users in a script to bypass insight but it will probably not happen so don’t worry
Yes. Scripting attacks can bypass Norton Insight on home computers. But, the attack method in the OP requires high privileges and it is a part of lateral movement in the already compromised local network. Without lateral movement, the attacker must find another way to deliver/run the executable (run_with_unhook.exe). In the home environment, this can be done via the Internet or USB drive - both are protected by Norton Insight.
It is possible to perform a similar attack filelessly by using scripting methods combined with process hollowing or similar methods, but this would be more complicated.
 

Vitali Ortzi

Level 22
Verified
Top Poster
Well-known
Dec 12, 2016
1,148
Yes. Scripting attacks can bypass Norton Insight on home computers. But, the attack method in the OP requires high privileges and it is a part of lateral movement in the already compromised local network. Without lateral movement, the attacker must find another way to deliver/run the executable (run_with_unhook.exe). In the home environment, this can be done via the Internet or USB drive - both are protected by Norton Insight.
It is possible to perform a similar attack filelessly by using scripting methods combined with process hollowing or similar methods, but this would be more complicated.
💯 %
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top