019. Here's Another Rootkit Remover Commonly Abused by Threat Actors

Hello everyone! One of my blog readers, Jefferson, suggested to blog about another tool commonly abused to disable AV and EDR - GMER

Back in a day, we even used during incident responce engagements, but nowasdays it's commonly abused by various ransomware gangs, for example, BlackSuit.

Despite the fact activity related to GMER may be legitimate, it's good to have proper detections and respond accordingly as it may be a ransomware precursor!

So, here're some detection opportunities:

  • Dropping SYS files with metadata related to GMER: "GMER", "gmer.sys", etc.
  • Creating a service for aforementioned SYS file
  • GMER execution with -killfile option
At the same time, GMER is detected quite well by many antivirus engines:


What does it mean? The most important thing - to respond properly!

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

001. The Zeltser Challenge

012. They Want to Know Everything About Your System!