The fact that it is “behavioural” doesn’t have anything to do with the way it operates. It needs internet because some machine learning models are impossible to run on your machine, they would take days, weeks, months.If behavioral need internet, why it's behavioral protecton?
They work the same way. One works with behaviour extracted through partial emulation, the other one works with behavioural features observed at runtime.i think you dont tell behavior, you telling heuristic.
sent you.
I also tested it with system watcher, internet was open and ksn was also connected but it did not block. But it's not recorded, if you want me to test sample with all modules and open internet, i will record it and send you after @Shadowra and @Khushal told me they tested my sample.The fact that it is “behavioural” doesn’t have anything to do with the way it operates. It needs internet because some machine learning models are impossible to run on your machine, they would take days, weeks, months.
i'm waiting video bro.I've got a bit of time tonight, so I'll install Kaspersky and test it.
(I'll do the same with Bitdefender because I want to see it too).
Different solutions have different ways of dealing with signed malware. Some may be oblivious to signed malware, others may need more indicators than just the digital signature. Kaspersky is not one of the oblivious, neither is Avast. Avast very quickly makes the digital signature the actual reason for detection.Another things with KSN or alternative of it is that they dont get digitally signed files, that's why if a virus really strongly fudded and signed, then KSN-like cloud technologies would ignore it.
i'm waiting video bro.
Maybe i can test AVG tonight with open internet. I worry it.Different solutions have different ways of dealing with signed malware. Some may be oblivious to signed malware, others may need more indicators than just the digital signature. Kaspersky is not one of the oblivious, neither is Avast. Avast very quickly makes the digital signature the actual reason for detection.
I can give source code?I don't think the Ransomware encrypts the data because the files are lost forever...
Expected results.Here are the tests!
Internet was disabled during the test.
View attachment 285217View attachment 285218View attachment 285219
Kaspersky did not block the attack.
I don't think the Ransomware encrypts the data because the files are lost forever...
It's more like a Wipper...
View attachment 285220Bitdefender blocked it on extraction by the anti-malware engine with one detection.
I can give source code?
it does encrypt data, i agree i am doing forensics.I can give source code?
It compromises the integrity of information is the right way to say it then, since you are doing forensics.it does encrypt data, i agree i am doing forensics.
Kaspersky Premium can be tweaked to not allow the execution of this file. Without the tweak, seems like there is no detection from the standard modules.@Trident Bro i just tested Kaspersky Premium with all module and connected to network and it didnot block, im uploading video.
Yeah i have often submitted Kaspersky such samples and their analysts always hesitate to add heuristics for Kryptik/Crypt Samples. Albeit i do think that Kaspersky might behave differently on a real machine as quoted multiple times by their experts.It compromises the integrity of information is the right way to say it then, since you are doing forensics.
It is malware and it must be detected.
Kaspersky Premium can be tweaked to not allow the execution of this file. Without the tweak, seems like there is no detection from the standard modules.
Yeah do DM.I can give source code?
Microsoft detects it, ESET doesn'tYou can if you want, even if it won't do me any good
I'd especially like to understand how you encrypt the data.
(I'm going to try it with Eset and Microsoft Defender with Anti-Ransomware enabled)
Microsoft detects? How? i cant believe right now.Microsoft detects it, ESET doesn't