JBE Posted September 24, 2015 Posted September 24, 2015 Hi all, We have had a recent outbreak of Malware ( a variant of Crypto Locker) on our network. We have endpoint, server security plus extra security. At present we are unable to find a rouge machine on our network. However, have had to recover most of the contents of our shared drive back from backups twice! Of course this virus normally infects by someone opening an attachment and I also know that it can't spread to networks shares via UNC path but can via a mapped drive. We use HAP + here and my question is that would it be possible for it to be transferred using HAP by an outside rouge machine, HAP + is set to map to our S:/ drive. Any help would be great Thanks.
fairm010 Posted September 24, 2015 Posted September 24, 2015 No that wouldnt be possible, unless you have .exe files allowed through HAP?
JBE Posted September 24, 2015 Author Posted September 24, 2015 just checking our settings and we did have all files *.* allowed. I have removed this..
fairm010 Posted September 24, 2015 Posted September 24, 2015 Even then, there is no way to my knowledge for malware to interact with the HAP site, let alone store login details etc. I dont think HAP is your suspect here.
nickbro Posted September 24, 2015 Posted September 24, 2015 The *.* rule only applies to admin users. Since HAP+ is pretty obscure most malware developers wouldn't look at HAP+ for distributing malware. If you have an AV on the server HAP+ will still trigger that AV to check the file once it's uploaded. HAP+ runs as an isolated user on the server (IIS AppPool\HAP), that user doesn't tend to have interactive execution rights, most rights to execute stuff only run in the IIS AppPool instance.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now