The Point of Sale (PoS) Malware Supplemental Rule Pack focuses on detecting compromised point of sale terminals, and contains more than 25 rules.
Attackers frequently target institutions that use Point of Sale (PoS) terminals to process credit card transactions in order to maximize financial gains from compromises. Attackers are able to accomplish this because a majority of PoS terminals retain credit card magnetic stripe data in plain text in RAM, allowing them to utilize RAM-scraping malware to harvest and exfiltrate credit card numbers.
While detecting RAM scraping is very difficult, the traditional mechanisms that these malware families use for persistence and command and control are often detectable by traditional means.
Initial deployment state
By default, all rules in the Point of Sale Malware Supplemental Rule pack are enabled.
Trellix recommends that you review each of these rules individually and read their descriptions in order to determine if they are suitable for your environment, detection strategy, and risk profile before determining whether or not to disable them for your environment.
Rules in the enhanced Windows rule pack
The rules that comprise the Enhanced Windows Rule Pack focus on the detection of major PoS malware families, and include:
ALINA: Process creation, HTTP communication using known URI or multiple user agents
BACKOFF: Windows process creation, HTTP communication using known URI or multiple user agents
BRUTPOS: Windows service started, HTTP communication using known URI or user agents
CHEWBACCA: HTTP communication using known URI or user agents
DECEBAL: Windows process creation, HTTP communication using known URI or user agents
DEXTER: HTTP communication using known URI’s or user agents
JACKPOS: Windows process creation, URI, and user agent
LAMPPOST: HTTP communication using known URI or user agents
LUSYPOS: Windows process creation
MOZART: Windows service started
RDASRV: Windows service started
SORAYA: HTTP communication using known user agents
GENERIC: Detection of multiple known PoS malware hashes