Jump to content

Recommended Posts

Posted

Hi all,

 

We have had a recent outbreak of Malware ( a variant of Crypto Locker) on our network. We have endpoint, server security plus extra security.

 

At present we are unable to find a rouge machine on our network. However, have had to recover most of the contents of our shared drive back from backups twice!

 

Of course this virus normally infects by someone opening an attachment and I also know that it can't spread to networks shares via UNC path but can via a mapped drive.

 

We use HAP + here and my question is that would it be possible for it to be transferred using HAP by an outside rouge machine, HAP + is set to map to our S:/ drive.

 

 

Any help would be great

 

Thanks.

Posted

The *.* rule only applies to admin users. Since HAP+ is pretty obscure most malware developers wouldn't look at HAP+ for distributing malware. If you have an AV on the server HAP+ will still trigger that AV to check the file once it's uploaded.

 

HAP+ runs as an isolated user on the server (IIS AppPool\HAP), that user doesn't tend to have interactive execution rights, most rights to execute stuff only run in the IIS AppPool instance.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...