Software

MS AntiSpyware and file locations

Microsoft has released a beta version of its antispyware program. Response from the IT community has been mixed so far, not surprisingly.

For instance, today we received a report about MS AntiSpyware flagging a suspicious file:

“c:winntsystem32notpad.exe” was detected as a Remote Administration Tool.

This file – which was a French version of notepad – would normally be called notepad.exe. For some reason, we don’t know why, the file was renamed as notpad.exe.

When we looked closely, it was clear what this file was. So we figured that MS AS had a faulty signature meaning this particular French version of notepad is detected as ItEye RAT.

Not every version (language, build) of every (Windows) file gets tested to check for false alarms, so this might have slipped by.

However we quickly realized that it was the combination of file name/location that made MS AntiSpyware go off.

In fact, the beta version of MS AntiSpyware detects any file with the name “notpad.exe” – even a completely empty one – residing in %sysdir% as being this particular RAT.

So at least a part of the “ItEye RAT” detection is strictly based on filename/location, which can result in situations like these.

Because of this, we think it’s best to detect files by file signatures, not location.

MS AntiSpyware and file locations

Your email address will not be published. Required fields are marked *

 

Reports

The leap of a Cycldek-related threat actor

The investigation described in this article started with one such file which caught our attention due to the various improvements it brought to this well-known infection vector.

Lazarus targets defense industry with ThreatNeedle

In mid-2020, we realized that Lazarus was launching attacks on the defense industry using the ThreatNeedle cluster, an advanced malware cluster of Manuscrypt (a.k.a. NukeSped). While investigating this activity, we were able to observe the complete life cycle of an attack, uncovering more technical details and links to the group’s other campaigns.

Sunburst backdoor – code overlaps with Kazuar

While looking at the Sunburst backdoor, we discovered several features that overlap with a previously identified backdoor known as Kazuar. Our observations shows that Kazuar was used together with Turla tools during multiple breaches in past years.

Subscribe to our weekly e-mails

The hottest research right in your inbox