Views:

Behaviors

  • Bypasses anti-virus products
  • Maintains persistence on the targeted machine
  • Runs as legitimate process by injecting to Windows process
  • Gains admin privileges and disables user account control (UAC)

Capabilities

  • Information Theft
  • Backdoor commands

Impact

  • Compromise system security - with backdoor capabilities that can execute malicious commands
  • Violation of user privacy - gathers user credentials, logs keystroke and steals user information

File Reputation

Detection/Policy/Rules Pattern Branch/Version Release Date
Backdoor.Win32.REMCOS.USMANEAGFE Backdoor.Win32.REMCOS.USMANEAGFG Backdoor.Win32.REMCOS.USMANEAGFM Backdoor.Win32.REMCOS.USMANEAGFN ENT OPR 15.747.00 March 17, 2020

Predictive Machine Learning

Detection Pattern Branch/Version
Troj.Win32.TRX.XXPE50FFF034 In-the-cloud

Web Reputation

Detection/Policy/Rules Pattern Branch/Version
URL Protection In-the-cloud

Anti Spam

Pattern Branch/Version Release Date
AS Pattern 5300 March 18, 2020

Solution Map - What should customers do?

Trend Micro Solution Major Product Latest Version Virus Pattern Anti-Spam Pattern Network Pattern Predictive Machine Learning Web Reputation
Endpoint Security ApexOne 2019 Update pattern via web console Not Applicable Update pattern via web console Enable Predictive Machine Learning Enable Web Reputation Service and update pattern via web console
OfficeScan XG (12.0) Not Applicable
Worry-Free Business Security Standard (10.0)
Advanced (10.0) Update pattern via web console
Hybrid Cloud Security Deep Security 12.0 Update pattern via web console Not Applicable Update pattern via web console Enable Predictive Machine Learning Enable Web Reputation Service and update pattern via web console
Email and Gateway Security Deep Discovery Email Inspector 3.5 Update pattern via web console Update pattern via web console Update pattern via web console Not Applicable Enable Web Reputation Service and update pattern via web console
InterScan Messaging Security 9.1 Not Applicable
InterScan Web Security 6.5
ScanMail for Microsoft Exchange 14.0
Network Security Deep Discovery Inspector 5.5 Update pattern via web console Not Applicable Update pattern via web console Not Applicable Enable Web Reputation Service and update pattern via web console

Recommendations

Threat Report

Blogs