Point of sale malware supplemental rule pack

Prev Next

The Point of Sale (PoS) Malware Supplemental Rule Pack focuses on detecting compromised point of sale terminals, and contains more than 25 rules.

Attackers frequently target institutions that use Point of Sale (PoS) terminals to process credit card transactions in order to maximize financial gains from compromises. Attackers are able to accomplish this because a majority of PoS terminals retain credit card magnetic stripe data in plain text in RAM, allowing them to utilize RAM-scraping malware to harvest and exfiltrate credit card numbers.

While detecting RAM scraping is very difficult, the traditional mechanisms that these malware families use for persistence and command and control are often detectable by traditional means.

Initial deployment state

By default, all rules in the Point of Sale Malware Supplemental Rule pack are enabled.

Trellix recommends that you review each of these rules individually and read their descriptions in order to determine if they are suitable for your environment, detection strategy, and risk profile before determining whether or not to disable them for your environment.

Rules in the enhanced Windows rule pack

The rules that comprise the Enhanced Windows Rule Pack focus on the detection of major PoS malware families, and include:

  • ALINA: Process creation, HTTP communication using known URI or multiple user agents

  • BACKOFF: Windows process creation, HTTP communication using known URI or multiple user agents

  • BRUTPOS: Windows service started, HTTP communication using known URI or user agents

  • CHEWBACCA: HTTP communication using known URI or user agents

  • DECEBAL: Windows process creation, HTTP communication using known URI or user agents

  • DEXTER: HTTP communication using known URI’s or user agents

  • JACKPOS: Windows process creation, URI, and user agent

  • LAMPPOST: HTTP communication using known URI or user agents

  • LUSYPOS: Windows process creation

  • MOZART: Windows service started

  • RDASRV: Windows service started

  • SORAYA: HTTP communication using known user agents

  • GENERIC: Detection of multiple known PoS malware hashes