[AV-Comparatives] Proactive protection against the WannaCry ransomware

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
It would be interesting to see WD's behavior here, in the case of the static detection fails.

https://malwaretips.com/threads/w-anna-cry-v2.71397/#post-630017
it's not easy to do a test with WD now because it's very likely to detect all samples by signatures. If we test it with the outdated signatures, if it triggers the cloud, it would block it, maybe
the best way to test it is to wait until there is a brand new variant which is undetected by either signatures or cloud
 
Last edited:

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
ummm but kaspersky is the nightmare of all cyber criminals.
Kaspersky is our hero.
Don't underestimate the power of kaspersky.
Sure, but I think what he meant is that no product is invincible and 100% secure, and keep in mind that this is the eternal struggle between the sword and the shield, and so always it will be.
 

Windows Defender Shill

Level 7
Verified
Well-known
Apr 28, 2017
326
Microsoft 10 Smart Screen should be able to detect, to the point where the user would be very aware they are running a risky file.

Or if set to block would not even give you the option.

Not even gonna mention the App lockdown settings Windows gives us now.
 

spaceoctopus

Level 16
Verified
Top Poster
Content Creator
Well-known
Jul 13, 2014
766
True,nothing is perfect,even Kaspersky which is a top product.Remembering some time ago when they discovered a malware that infiltrated,and was lingering in their core infrastructures.Despite the high level of security at that level.Proof that nothing is 100% sure and effective.
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
True,nothing is perfect,even Kaspersky which is a top product.Remembering some time ago when they discovered a malware that infiltrated,and was lingering in their core infrastructures.Despite the high level of security at that level.Proof that nothing is 100% sure and effective.
That alleged Duqu 2.0 based fileless malware resided for quite some time in their machines when they suspected unusual network activity.
That was a malware of a state-sponsored cyberattack level and detecting it ultimately helped them understand and analyse their technique to be prepared, and avoid spoofing in ways they understood.
 

spaceoctopus

Level 16
Verified
Top Poster
Content Creator
Well-known
Jul 13, 2014
766
That alleged Duqu 2.0 based fileless malware resided for quite some time in their machines when they suspected unusual network activity.
That was a malware of a state-sponsored cyberattack level and detecting it ultimately helped them understand and analyse their technique to be prepared, and avoid spoofing in ways they understood.
Yes, it was what i was talking about.But the interesting thing in this case,is instead of attacking individual Pcs, someone could attack any security provider in it's main infrastructures and compromise every computers connected to it.Just seeing the case of Wannacry, it seems almost everything is possible.
 

Game Of Thrones

Level 6
Verified
Well-known
Jun 5, 2014
276
True,nothing is perfect,even Kaspersky which is a top product.Remembering some time ago when they discovered a malware that infiltrated,and was lingering in their core infrastructures.Despite the high level of security at that level.Proof that nothing is 100% sure and effective.
this is good! because the vendors that get hit by something like this will do better in the future to defend their infrastructures. many other even do not know that they are compromised. finding this kind of issues will help them to make better tactics.
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
this is good! because the vendors that get hit by something like this will do better in the future to defend their infrastructures. many other even do not know that they are compromised. finding this kind of issues will help them to make better tactics.
True said! That's one occurrence that Kaspersky could actually benefit in terms of learning and being prepared, for themselves and their clients. You never can be sure if you're clean, and getting to know in itself is a feat.
Eventually, they would bring some radical improvement in strategies to deal with potential fileless malware and targeted attacks.
Against such fileless malware that Kaspersky reported in many financial institutes and enterprises, Kaspersky has implemented plans like their Anti-Targeted Attack Platform for advanced analysis and detection of such attacks.
 

Maxxx58

Level 13
Verified
Dec 20, 2014
619
Kaspersky on my computer just showed that :D
Kaspersky_Wannacry.PNG
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top