Events and Digital signers

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Events and Digital signers

L4 Transporter

Hi

 

so I have an application https://processhacker.sourceforge.io/ our dev guys want to use.

 

it shows up as begnin in wildfire, but its blocked signer override ???

 

OKay how / where is that configured I didn't do that.

Can I over ride 

 

and how can I add in our companies signing cert

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@Alex_Samad,

The signer of this application is placed in Traps blacklisted signers; you would need to override this by whitelisting the signer Wen Jia Liu; but I would generally recommend not doing so unless you've fully analyzed the EXE and verified it isn't doing anything abnormal, as PAN is usually pretty good about actually only blocking known bad signers and that file doesn't have the best VirusTotal report

 

edit:

To whitelist a signer go into your Malware profile and it'll be under the 'Examine Portable Executables and DLLs' section under "Whitelist Signers". DOCS

Just FYI I would recommend against whitelisting external signers. I would utilize the Whitelist Files function instead, so you can verify that whatever whitelisted EXE is actually secure. 

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

@Alex_Samad,

The signer of this application is placed in Traps blacklisted signers; you would need to override this by whitelisting the signer Wen Jia Liu; but I would generally recommend not doing so unless you've fully analyzed the EXE and verified it isn't doing anything abnormal, as PAN is usually pretty good about actually only blocking known bad signers and that file doesn't have the best VirusTotal report

 

edit:

To whitelist a signer go into your Malware profile and it'll be under the 'Examine Portable Executables and DLLs' section under "Whitelist Signers". DOCS

Just FYI I would recommend against whitelisting external signers. I would utilize the Whitelist Files function instead, so you can verify that whatever whitelisted EXE is actually secure. 

Hi

 

What I have done is over ridden the hash, happy with the file maybe not happy with the rest of the signed stuff.

Now a question about whitelisting certs.

Thats a text string and its regexed against certs ?

I can't find what is acceptable for that field.

 

can I do 

 

^Wen Jia Liu$

or can I only do 

Wen Jia Liu

 

does that mean that it will accept "Wen Jia Liu Reall Bad"  as well or even "OWen Jia LiuS"

 

thanks

 

 

 

  • 1 accepted solution
  • 3908 Views
  • 2 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!