Events and Digital signers

Reply
L4 Transporter

Events and Digital signers

Hi

 

so I have an application https://processhacker.sourceforge.io/ our dev guys want to use.

 

it shows up as begnin in wildfire, but its blocked signer override ???

 

OKay how / where is that configured I didn't do that.

Can I over ride 

 

and how can I add in our companies signing cert

 

L7 Applicator

Re: Events and Digital signers

@Alex_Samad,

The signer of this application is placed in Traps blacklisted signers; you would need to override this by whitelisting the signer Wen Jia Liu; but I would generally recommend not doing so unless you've fully analyzed the EXE and verified it isn't doing anything abnormal, as PAN is usually pretty good about actually only blocking known bad signers and that file doesn't have the best VirusTotal report

 

edit:

To whitelist a signer go into your Malware profile and it'll be under the 'Examine Portable Executables and DLLs' section under "Whitelist Signers". DOCS

Just FYI I would recommend against whitelisting external signers. I would utilize the Whitelist Files function instead, so you can verify that whatever whitelisted EXE is actually secure. 

Highlighted
L4 Transporter

Re: Events and Digital signers

Hi

 

What I have done is over ridden the hash, happy with the file maybe not happy with the rest of the signed stuff.

Now a question about whitelisting certs.

Thats a text string and its regexed against certs ?

I can't find what is acceptable for that field.

 

can I do 

 

^Wen Jia Liu$

or can I only do 

Wen Jia Liu

 

does that mean that it will accept "Wen Jia Liu Reall Bad"  as well or even "OWen Jia LiuS"

 

thanks

 

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!