Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Windows Firewall with Advanced Security –
- Blocking Outbound Connection
- Credits to Daniel Streefkerk (https://daniel.streefkerkonline.com/2017/10/24/mitigate-commodity-malware-attacks-with-windows-firewall-rules/) @dstreefkerk
- I have added a few addition in his Firewall configuration that adds extra defensive layer.
- Block Internet Access - conhost.exe (x64)
- %SystemRoot%\System32\conhost.exe
- Block Internet Access - cscript.exe
- %SystemRoot%\SysWOW64\cscript.exe
- Block Internet Access - cscript.exe (x64)
- %SystemRoot%\System32\cscript.exe
- Block Internet Access – cmstp.exe
- %SystemRoot%\SysWOW64\cmstp.exe
- Block Internet Access – calc.exe (x64)
- %SystemRoot%\SysWOW64\calc.exe
- Block Internet Access – calc.exe
- %SystemRoot%\SysWOW64\calc.exe
- Block Internet Access – cmstp.exe (x64)
- %SystemRoot%\System32\cmstp.exe
- Block Internet Access - wscript.exe
- %SystemRoot%\SysWOW64\wscript.exe
- Block Internet Access - wscript.exe (x64)
- %SystemRoot%\System32\wscript.exe
- Block Internet Access - mshta.exe
- %SystemRoot%\SysWOW64\mshta.exe
- Block Internet Access - mshta.exe (x64)
- %SystemRoot%\System32\mshta.exe
- Block Internet Access - bitsadmin.exe
- %SystemRoot%\SysWOW64\bitsadmin.exe
- Block Internet Access – bitsadmin.exe (x64)
- %SystemRoot%\System32\bitsadmin.exe
- Block Internet Access - csrss.exe
- %SystemRoot%\SysWOW64\csrss.exe
- Block Internet Access – csrss.exe (x64)
- %SystemRoot%\System32\csrss.exe
- Block Internet Access - devicedisplayobjectprovider.exe
- %SystemRoot%\SysWOW64\devicedisplayobjectprovider.exe
- Block Internet Access – devicedisplayobjectprovider.exe (x64)
- %SystemRoot%\System32\devicedisplayobjectprovider.exe
- Block Internet Access – lsass.exe
- %SystemRoot%\SysWOW64\lsass.exe
- Block Internet Access – lsass.exe (x64)
- %SystemRoot%\System32\lsass.exe
- Block Internet Access – presentationhost.exe
- %SystemRoot%\SysWOW64\presentationhost.exe
- Block Internet Access – presentationhost.exe (x64)
- %SystemRoot%\System32\presentationhost.exe
- Block Internet Access – wsmprovhost.exe
- %SystemRoot%\SysWOW64\wsmprovhost.exe
- Block Internet Access – wsmprovhost.exe (x64)
- %SystemRoot%\System32\wsmprovhost.exe
- Block Internet Access – eventvwr.exe
- %SystemRoot%\SysWOW64\eventvwr.exe
- Block Internet Access – eventvwr.exe (x64)
- %SystemRoot%\System32\eventvwr.exe
- Block Internet Access – mmc.exe
- %SystemRoot%\SysWOW64\mmc.exe
- Block Internet Access – mmc.exe (x64)
- %SystemRoot%\System32\mmc.exe
- Block Internet Access - runscripthelper.exe
- %SystemRoot%\SysWOW64\runscripthelper.exe
- Block Internet Access – runscripthelper.exe (x64)
- %SystemRoot%\System32\runscripthelper.exe
- Block Internet Access – notepad.exe
- %SystemRoot%\SysWOW64\notepad.exe
- Block Internet Access – notepad.exe (x64)
- %SystemRoot%\System32\notepad.exe
- Block Internet Access - powershell_ise.exe
- %SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe
- Block Internet Access - powershell_ise.exe (x64)
- %SystemRoot%\System32\WindowsPowerShell\v1.0\powershell_ise.exe
- Block Internet Access - powershell.exe
- %SystemRoot%\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
- Block Internet Access - powershell.exe (x64)
- %SystemRoot%\System32\WindowsPowerShell\v1.0\powershell.exe
- Block Internet Access - regsvr32.exe
- %SystemRoot%\SysWOW64\regsvr32.exe
- Block Internet Access - regsvr32.exe (x64)
- %SystemRoot%\System32\regsvr32.exe
- Block Internet Access - rundll32.exe
- %SystemRoot%\SysWOW64\rundll32.exe
- Block Internet Access - rundll32.exe (x64)
- %SystemRoot%\System32\rundll32.exe
- Block Internet Access - msdt.exe
- %SystemRoot%\SysWOW64\msdt.exe
- Block Internet Access - msdt.exe (x64)
- %SystemRoot%\System32\msdt.exe
- Block Internet Access - dfsvc.exe - 2.0.50727
- %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
- Block Internet Access - dfsvc.exe - 2.0.50727 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v2.0.50727\dfsvc.exe
- Block Internet Access - dfsvc.exe - 4.0.30319
- %SystemRoot%\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
- Block Internet Access - dfsvc.exe - 4.0.30319 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
- Block Internet Access - ieexec.exe - 2.0.50727
- %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
- Block Internet Access - ieexec.exe - 2.0.50727 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v2.0.50727\IEExec.exe
- Block Internet Access - MSBuild.exe - 2.0.50727
- %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
- Block Internet Access - MSBuild.exe - 2.0.50727 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v2.0.50727\MSBuild.exe
- Block Internet Access - MSBuild.exe - 3.5
- %SystemRoot%\Microsoft.NET\Framework\v3.5\MSBuild.exe
- Block Internet Access - MSBuild.exe - 3.5 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v3.5\MSBuild.exe
- Block Internet Access - MSBuild.exe - 4.0.30319
- %SystemRoot%\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
- Block Internet Access - MSBuild.exe - 4.0.30319 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe
- Block Internet Access - InstallUtil.exe - 2.0.50727
- %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
- Block Internet Access - InstallUtil.exe - 2.0.50727 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v2.0.50727\InstallUtil.exe
- Block Internet Access - InstallUtil.exe - 4.0.30319
- %SystemRoot%\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
- Block Internet Access - InstallUtil.exe - 4.0.30319 (x64)
- %SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement