True Positive / no incident / evasion / self made alerts helped to detect

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

True Positive / no incident / evasion / self made alerts helped to detect

L4 Transporter

Hello dear community, 

 

got an 2 hour infection on a fat client from this https://www.virustotal.com/gui/file/79e3e243726a8b29b4cf74576e364ce98dfadb5bd182d8d1ed55255e70defc2c...

This little guy was evading cortex xdr pro. 

Whatch out and fill your blocklist, because they getting better and better. 

 

Initial access was a google drive link and the pw protected rar/zip with about 120 MB size. 

 

If you are interested with wich self made bioc we detected it let me know. 

 

BR

 

Rob

 

1 accepted solution

Accepted Solutions

Hi @RFeyertag 

For Cortex XDR coverage information, please submit a TAC case and share your observation and workaround you did on the same for team to review and update.

 

Thanks

 

View solution in original post

3 REPLIES 3

L4 Transporter

Hi @RFeyertag,

 

Thanks for sharing this with the community!

Hey @anlynch!

 

it would be nice if there could be a new rule for process which is not browser communicating to steamcommunity and/or t.me. And this rule should terminate this process. 

Because wildfire is not getting a 300 MB scr file to analyze. So it flew completely under the radar. 

This is one of the best evasion technique I've ever seen and I am a little bit proud that I detected it with much efort creating new rules to detect this peace of best stealer trojan.  

 

BR

 

Rob

 

 

Hi @RFeyertag 

For Cortex XDR coverage information, please submit a TAC case and share your observation and workaround you did on the same for team to review and update.

 

Thanks

 

  • 1 accepted solution
  • 1035 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!