This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Protect against malware Adrozek?

Good afternoon, 

I would like to confirm if the machine-learning feature of Sophos can protect us againts the new major browser malware Adrozek. 

Further information about can be find here:

https://arstechnica.com/information-technology/2020/12/ongoing-malware-attacks-are-hitting-users-of-4-major-browsers/

Detailed one : https://www.microsoft.com/security/blog/2020/12/10/widespread-malware-campaign-seeks-to-silently-inject-ads-into-search-results-affects-multiple-browsers

My understanding is that a standard signature protection can't beat the countermesure Adrozek are taking.

Also I'm not sure blocking  Audiolava.exe, QuickAudio.exe, and converter.exe can a real protection here.

That said, in this one I need your help to tell me if Sophos already have something against it or if I need to look at something else to block it.

Regards,



This thread was automatically locked due to age.
Parents
  • Hi ,

    Based with our labs team confirmation, we are detecting the files through generic malware detection (Troj/Agent-BEQV) and also through ML based detection.
    In addition There is no mention of hashes or IPs on Microsoft blog. To help us strengthened the protection that we can offer for this type of Malware, Please submit to us any sample file related to this malware in order for our labs team to further check to it. 

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hi ,

    Based with our labs team confirmation, we are detecting the files through generic malware detection (Troj/Agent-BEQV) and also through ML based detection.
    In addition There is no mention of hashes or IPs on Microsoft blog. To help us strengthened the protection that we can offer for this type of Malware, Please submit to us any sample file related to this malware in order for our labs team to further check to it. 

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children
No Data