MalwareBytes has an local database on the machine. It is a SQLite database. It contains settings for various properties such as licensing, malware identified, and known-good and known-bad lists. This is standard anti-malware stuff. The database with "ThankYouForChoosingMalwarebytes" is the less interesting database, as it mostly contains settings (this can still be abused though).
Regardless, MalwareBytes does a couple of things with this SQLite stuff
MalwareBytes establishes a kernel-mode minifilter (mbam.sys). They setup minifilter callback routines to handle events on the system for process creation, process loading, and registry modification (Image 1)
In other words, MalwareBytes is notified immediately when a process is created or an executable image is loaded. When a process is created or an executable image is loaded, MalwareBytes has special functionality to temporarily "pause" execution so it can review it.
However, this "pause" happens faster than you or I can blink. Computers are fast.
The mbam.sys creates an internal record of all processes running. When a new process is loaded it is added to this internal record. When a program is closed, it is removed from the record. It does this so it doesn't accidentally review or "pause" the same process twice.
When a program is added to this list, the kernel-mode component communicates with the user-mode component that then signals and connects to a local SQLite database. The SQLite database then does a lookup to determine if the process "paused" is known or unknown (Image 2)
However, it should be noted, Image 2 is not the important SQLite instance I am looking for. This is something else MalwareBytes uses (and communicates to with kernel-mode components). The point still stands.
If it is known, it communicates back to the kernel-mode component that is it known. If it known, and known to be malicious, MalwareBytes takes action on the program attempting to run and immediately stops execution. If it is known to be good, MalwareBytes marks it internally as "seen" and keeps it in it's internal record.
Image 3 is from the internal database they use. It's fairly large and is mostly settings. I still haven't find where the really nice, big, and important dataset they use is. It requires more poking and more sticks.
Throughout the first year of Donald Trump’s second administration, Vanity Fair writer Chris Whipple has interviewed Susie Wiles, White House chief of staff, amid each moment of crisis.
His insider’s account of Trump 2.0 joins the photography of Christopher Anderson for a portrait of power—and peril.
Part 1 of 2: https://t.co/FTRehEMfLH
🚨🇺🇸 Labor Day Giveaway 🇺🇸🚨
I’m giving away a CompTIA Security+ voucher! 🎉🎉
How to enter:
• Like & RT this post
• Comment or tag a friend
Winners announced this Friday!
Good Luck!
Interesante cambio en la distribución brasileña que comúnmente entrega el malware #Mekotio en Chile 🇨🇱, ahora instala directamente #PDQConnect (https://t.co/6xQhGcoUHh), al menos en primera instancia 🤔
Una tendencia que ha estado observando @k3yp0d también https://t.co/HMF30vmz2Q 🦾
Los actores maliciosos están suplantando la imagen de la Comisión Nacional de Seguridad de Tránsito / CONASET.
IoCs por @joy_dragon 🫡
- https[:]//retromusicfm[.]com/CONASET/RegularizacionProtocoloConaset_2024-4852319[.]pdf?11117251
- https[:]//laburantes[.]org/conaset/Infraccione/Informe/ver/Octubre/?hash=CONASET
- https[:]//apexremodeling[.]org/CONASET/Infraccione/Informe/ver/Octubre/p/d/f/?hash=CONASET?734402459
- https[:]//apexremodeling[.]org/arq/InformeInfraccioneCONASET[.]msi?959176483
Por supuesto, el Agente PDQ tiene 0 detecciones en VirusTotal ☑️
I HATE THAT NOWHERE ON THE INTERNET HAS EXACT SEARCH ANYMORE. YOU CAN PUT ALL THE DOUBLE QUOTES YOU WANT AND IT STILL FUZZY MATCHES OR STRAIGHT UP DOES """SYNONYMS""". GOOGLE SUCKS NOW. EVERYTHING SUCKS ENSHITTIFICATION OF EVERYTHING.
GUYSSS, @CrowdStrike’s global threat report for 2024 released TODAY!!! it’s free, contains a plethora of statistics about threat intelligence, incident response, what’s going on in the cyber world, and more that your org can use! check it out!!! 🫡
https://t.co/fvMyfkYRCg
Llevamos 2 incidentes de #ransomware con el mismo patrón: los joputas entran, atacan el veeamBackup/vSphere, trincan creds, roban datos, borran los backup del NAS,te paran las VM y te detonan el cifrador en los datastores. Es un desastre pq no hay nada q revisar desde #DFIR (1/2)