019. Here's Another Rootkit Remover Commonly Abused by Threat Actors
Hello everyone! One of my blog readers, Jefferson, suggested to blog about another tool commonly abused to disable AV and EDR - GMER.
Back in a day, we even used during incident responce engagements, but nowasdays it's commonly abused by various ransomware gangs, for example, BlackSuit.
Despite the fact activity related to GMER may be legitimate, it's good to have proper detections and respond accordingly as it may be a ransomware precursor!
So, here're some detection opportunities:
- Dropping SYS files with metadata related to GMER: "GMER", "gmer.sys", etc.
- Creating a service for aforementioned SYS file
- GMER execution with -killfile option
At the same time, GMER is detected quite well by many antivirus engines:
What does it mean? The most important thing - to respond properly!
See you tomorrow!
Comments
Post a Comment