av-registry-exclusion-spray
Defense-evasion technique: systematically add directory/file exclusions to the registry hives of every major endpoint-security product on the victim machine, including both Western and Chinese vendors. Reduces the probability that any installed AV will scan the staging directory or quarantine the payload. Observed in a lightweight .NET Framework 4.6.2 stage-1 dropper (
8f288492) distributed via Amadey. ^[/intel/analyses/8f28849296f4c10a3271aec35441bc7421be693be966f749cf50120730adb348.html]
What It Does
The malware iterates a hardcoded list of AV product names and writes exclusion registry keys under each vendor's hive. This is a "spray" approach — instead of targeting only Windows Defender (the most common target), it covers eleven vendors to maximize survivability on diverse endpoint stacks.
Observed Vendor List
| Vendor | Registry Path (observed) | Notes |
|---|---|---|
| Windows Defender | SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths |
Standard Microsoft path |
| ESET | SOFTWARE\ESET\Exclusions |
European NOD32/Endpoint |
| AVG | SOFTWARE\AVG\Exclusions |
Acquired by Avast; still distinct hive |
| Bitdefender | SOFTWARE\Bitdefender\Exclusions |
Romanian vendor |
| Kaspersky | SOFTWARE\KasperskyLab\Exclusions |
Russian vendor |
| Norton | SOFTWARE\Norton\Exclusions |
Symantec legacy |
| McAfee | SOFTWARE\McAfee\Exclusions |
Intel/Trellix legacy |
| Tencent | SOFTWARE\Tencent\TAV\Exclusions |
Chinese endpoint (Tencent Anti-Virus) |
| Avast | SOFTWARE\AVAST Software\Avast\Exclusions |
Czech vendor |
| 360 Safe | SOFTWARE\360Safe\scan\Trusted |
Chinese vendor; path is Trusted not Exclusions |
| Huorong (火绒) | SOFTWARE\Huorong\Sysdiag\WhiteList |
Chinese vendor; misspelled Mhuorong in binary |
Code Pattern
The exclusion list is stored as a static string array in the .NET class X7Y9Z.Q8W4K, loaded via InitAvList, then written via Registry.SetValue in a loop inside AddExclusions. The target path (pathToExclude) is typically the staging directory where core.exe will be dropped. ^[/intel/analyses/8f28849296f4c10a3271aec35441bc7421be693be966f749cf50120730adb348.html]
Detection
- Registry event logs (Sysmon Event ID 13, Windows 4657) showing rapid sequential
SetValueoperations across multiple vendorExclusionsorWhiteListkeys within the same process lifetime. - Process creation of a .NET binary immediately followed by
powershell.exewithAdd-MpPreference -ExclusionPathandSet-MpPreference -DisableRealtimeMonitoring $true. - The
360Safe\scan\TrustedandHuorong\Sysdiag\WhiteListpaths are high-signal indicators — legitimate software rarely writes there.
Defensive Countermeasures
- Tamper-protection on AV registry hives (modern ESET, Kaspersky, and Defender have this enabled by default; the spray will fail on these if tamper protection is active).
- Behavioral detection: flag any process that writes to more than two distinct AV vendor registry hives within a 5-second window.
Pages Where Observed
- 9d2ca3 — Fifth confirmed build morph under this contested OpenCTI label; the 11-vendor spray is unique to this sibling (
8f288492). - Related but narrower: defender-exclusion-via-powershell — prior samples only targeted Windows Defender via PowerShell.