Can SMG detect and remove malicious programs hidden through ZIP file concatenation technology?
search cancel

Can SMG detect and remove malicious programs hidden through ZIP file concatenation technology?

book

Article ID: 385251

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

This is in reference to external articles where hackers use ZIP file concatenation to evade detection.

Resolution

In Protection Highlight bulletin, "Symantec's advanced parser within the Static Data Scanner (SDS) is specifically designed to manage such anomalies. It can accurately parse concatenated ZIP archives, ensuring that malicious files such as the JavaScript downloaders used in the Smokeloader attack, are extracted and effectively detected." Where SDS is used, SMG would delete the entire concatenated ZIP (as opposed to removing single malicious file from within the ZIP).

Additional Information