App Review A brief look at Voodooshield

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
L

Lucent Warrior

Thread author
@Lucent Warrior did some samples bypass VoodooShield or everything was blocked? I watched the video but I didn't understand. Thanks in advance
Nothing bypassed VS in this test. In the beginning what you probably seen was the one process still running in the Local Sandbox that i manually killed. As of now, if a process that is run in the local sandbox does not self/auto terminate, then you either have to kill it manually via the process or restart the system which resets the sandbox.
 

TheMalwareMaster

Level 21
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
Nothing bypassed VS in this test. In the beginning what you probably seen was the one process still running in the Local Sandbox that i manually killed. As of now, if a process that is run in the local sandbox does not self/auto terminate, then you either have to kill it manually via the process or restart the system which resets the sandbox.
Thank you. Did you choose manually the "sandbox" option? You didn't click quarantine or block right?
 
L

Lucent Warrior

Thread author
When LW was testing in Malware Hub (with different name) lots of other members didn't get smart screen warning but he always do.
Malware pack was the same.
We could't not figure out why is that...o_O

"Guest"
Windows 10 pro
Local account
licensed/activated
fully updated/patched
@default settings in OS "with the exception of location and similar settings disabled.

"Vm"
Vmware workstation pro 12
complete guest isolation
NAT networking

"Product "Voodooshield"
Default settings "other then analysis tools that have been whitelisted"

In this particular test, VS is run with windows default security with Windows Defender being disabled as to not interfere with the test/samples. The rest is clearly visible.
 
L

Lucent Warrior

Thread author
Can you confirm that a couple of time there was a debate about that in Malware Hub?
I can confirm that it was discussed, and i can also confirm that the OS file reputation system is supposed to work exactly as it does in my video. What the few of your are doing different that produces your results is beyond me as im not sitting in front of your systems.
 
Last edited by a moderator:

harlan4096

Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,915
Currently I'm also getting W10 SmartScreen warnings in many samples when I test in MWHub, but usually don't upload the screen-shots of it, I'm testing KTS2017 not SS and I have to ignore its warning to run the samples ;)

In fact I also get W10 SS warnings when I only check reputation of a sample with VT Hash Checker :)
 

_CyberGhosT_

Level 53
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Aug 2, 2015
4,286
1. they are not always caught by smartscreen, just most.
2. very little detail in the OS file reputation system still makes it hard for a novice to know which way to turn, only information they receive with those is that the file is unknown to Smartscreen and they recommend "not running".
3. once the file has been let past smartscreen, it is totally up to the tested product to stop it or the system becomes infected.
4. most importantly, this is a brief review of the product, testing this method allowed me to show all aspects of dealing with a file via this product, and the ways to make choices/decisions.
Exactly, and thats what my initial comment focused on.
I could see that was your aim with this video, and you did a remarkable job. Thanks :)
 

Windows_Security

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 13, 2016
1,298
[QUOTE="Lucent Warrior[/QUOTE]

Maybe handy when you start or end the video with what your verdicts is and maybe sum up how it did in protection (that is why other member probably asked whether or not VS let something blocked everything).

So what is your verdict?

Thanks for the video
 
L

Lucent Warrior

Thread author
Lucent Warrior

Maybe handy when you start or end the video with what your verdicts is and maybe sum up how it did in protection (that is why other member probably asked whether or not VS let something blocked everything).

So what is your verdict?

Thanks for the video

Samples #8
Dynamic test 8/8

Test subject correctly blocked/quarantined samples after execution @ default settings. Based upon my testing so far with VS, it is solid, and very capable.
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top