HitmanPro.Alert
#5
Information 
Quote:HitmanPro.Alert 3.8.12 Build 899 Released

Changelog (compared to build 891):
  • Added New Cobalt Strike single-stage mitigation. When Cobalt Strike Beacon temporary de-cloakes in memory to retrieve new commands from the adversary, HitmanPro.Alert will hold and inspect the decrypted memory area for the presence of Beacon.
    Note: In a normal multi-stage scenario, Cobalt Strike Beacon is already proactively blocked by our patented HeapHeapProtect mitigation. This new Cobalt Strike mitigation now also thwarts the single-stage scenario. And upon detection of Beacon it also extracts and reports the full Cobalt Strike C2 profile configuration from memory.
  • Added DNS stager detection, when – for example – Cobalt Strike Beacon communicates over DNS with command-and-control (C2).
  • Added SysCall mitigation to every process so it now also blocks the Heaven’s Gate defense evasion technique in malware. The Heaven's Gate technique allows 32-bit malware running on 64-bit systems to hide API calls by switching to a 64-bit environment.
  • Added CookieGuard mitigation. It protects (MFA) session cookies and passwords stored in popular Chromium based web browsers, like Google Chrome and Microsoft Edge on Chromium.
  • Added an extra message box when an update is pending, and the user clicks on the associated flyout. The message informs the user that the machine must be restarted before the update is actually applied.
  • Fixed stack pivot exploit mitigation so it no longer triggers incorrectly on Internet Explorer loading a digital rights management (DRM) related library for streaming DRM protected content.
  • Fixed APC Violation mitigation so it now correctly identifies process injection from VMware.
  • Fixed Code Cave mitigation so it now plays nice with DRM code from gaming company Electronic Arts (EA).
  • Fixed Kernel32Trap mitigation so it no longer causes issues with certain code compiled with Visual Studio.
  • Improved CryptoGuard 5 anti-ransomware engine. For example, the note spray evaluator is more tolerant when installers drop the same text file across many folders.
  • Improved threat termination. It's now even more robust, especially when the threat runs with high privileges outside of user session(s).
  • Improved compatibility with certain games that perform tricks that trigger our main thread hijacking protection (part of Hollow Process Mitigation).
Over the next days. all users of HitmanPro.Alert should get this new build through automatic update! Beware though, we no longer support or update HitmanPro.Alert builds running on Windows 7 RTM (no service pack), Windows Vista and Windows XP. This is because Microsoft mandates the use of SHA-2 to sign our code. These older versions of Windows only support SHA-1 and would not allow our new driver to load.

If you want to update now, manually, use this link: https://dl.surfright.nl/hmpalert3b899.exe
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Messages In This Thread
HitmanPro.Alert - by silversurfer - 29 December 18, 10:45
RE: HitmanPro.Alert (Sophos Product) - by jasonX - 29 December 18, 21:43
HitmanPro.Alert 3.8.12 Build 899 - by harlan4096 - 26 May 21, 09:48
HitmanPro.Alert 3.8.19 Build 923 - by harlan4096 - 02 December 21, 11:29
HitmanPro.Alert 3.8.22 Build 947 - by harlan4096 - 20 September 22, 06:02
HitmanPro.Alert 3.8.25 Build 975 - by harlan4096 - 15 December 23, 10:29
RE: HitmanPro.Alert - by jasonX - 19 December 23, 03:12
HitmanPro.Alert 3.8.26 Build 979 - by harlan4096 - 08 February 24, 09:39
RE: HitmanPro.Alert - by jasonX - 08 April 24, 09:43
RE: HitmanPro.Alert - by jasonX - 01 March 25, 09:20

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Wikipedia sees decline in human pageview...
Wikipedia has reve...harlan4096 — 11:30
Google announces end of many of its Priv...
When Google announ...harlan4096 — 11:29
Xubuntu's website was hacked to spread a...
Xubuntu's website ...harlan4096 — 07:19
EPIM PRO
NOTE Astonsoft ...jasonX — 18:32
PrivadoVPN - Secure Every Device with On...
PrivadoVPN - Secure ...jasonX — 17:45

[-]
Birthdays
Today's Birthdays
avatar (47)vikgoMam
Upcoming Birthdays
avatar (47)Michaelaceve
avatar (37)QuadirLigh
avatar (38)Mblippek
avatar (44)viecontAceve
avatar (40)Michaelcrini

[-]
Online Staff
There are no staff members currently online.

>