This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Protect against malware Adrozek?

Good afternoon, 

I would like to confirm if the machine-learning feature of Sophos can protect us againts the new major browser malware Adrozek. 

Further information about can be find here:

https://arstechnica.com/information-technology/2020/12/ongoing-malware-attacks-are-hitting-users-of-4-major-browsers/

Detailed one : https://www.microsoft.com/security/blog/2020/12/10/widespread-malware-campaign-seeks-to-silently-inject-ads-into-search-results-affects-multiple-browsers

My understanding is that a standard signature protection can't beat the countermesure Adrozek are taking.

Also I'm not sure blocking  Audiolava.exe, QuickAudio.exe, and converter.exe can a real protection here.

That said, in this one I need your help to tell me if Sophos already have something against it or if I need to look at something else to block it.

Regards,



This thread was automatically locked due to age.
Parents
  • Hi GlenSen,

    Thanks for taking the time to reply to me, Malware Adrozek is a polymorphic malware that relates to more than 160 different domains and more than 17'000 uniques URLs. Tracking this malware by IP or Hashes, will not be doable (I think, I'm not an malware expert).

    Please tell me if I'm wrong, but I think a good way to track it is with the new ML (Machine learning) feature that Sophos is offering. By looking at the way the malware acts and preventing these type of actions:

    • browser extensions installed by the malware
    • Browser DLL edited
    • Add REG keys to prevent browsers to be updated
    • Multiple other REG keys edited

    Best regards,

Reply
  • Hi GlenSen,

    Thanks for taking the time to reply to me, Malware Adrozek is a polymorphic malware that relates to more than 160 different domains and more than 17'000 uniques URLs. Tracking this malware by IP or Hashes, will not be doable (I think, I'm not an malware expert).

    Please tell me if I'm wrong, but I think a good way to track it is with the new ML (Machine learning) feature that Sophos is offering. By looking at the way the malware acts and preventing these type of actions:

    • browser extensions installed by the malware
    • Browser DLL edited
    • Add REG keys to prevent browsers to be updated
    • Multiple other REG keys edited

    Best regards,

Children