There is no option to upload files in messages.Can you please DM the sample?
The obfuscated code is in the replies of the Reddit post.
I only copied the code and pasted in notepad and saved as cmd file.
There is no option to upload files in messages.Can you please DM the sample?
Symantec is back; looks was having a nap
Anywhere i can download Symantec ?
A malicious code of classic clickfix attack, copied and pasted into notepad, saved as cmd file, checked by VT: only Symantec could detect.
View attachment 295197
One more clickfix script detected by Symantec endpoint protection; it's getting real good with scripts, contrary to its reputation.
View attachment 295328
One more clickfix script detected by Symantec endpoint protection; it's getting real good with scripts, contrary to its reputation.
View attachment 295328
The previous one was added to K on VT after submitting it on K portal.submit to k?
| Feature | Norton (Symantec) | AVG |
| Cleanup Success | High (Includes Expert Help) | Good (Best via Boot-Scan) |
| Repairing OS Files | Very Good | Average |
| User Intervention | Automated & Hands-off | Requires more manual setup |
submit to k?
K7 is improving.K7 now join the list VirusTotal
I think they are copying from Kaspersky.K7 is improving.
Good one!
typical indian mindset of copying russians as they have done in defense.I think they are copying from Kaspersky.
The previous sample was first detected by Symantec also.
Then I submitted to Kaspersky; it was detected, than added to VT.
Later QuickHeal detected it also on VT.
and Chinese copying the American IOS in Xiaomi MIUI, then HyperOS later.typical indian mindset of copying russians as they have done in defense.
View attachment 295340
4 hours ago already in database. Very fast indeed.
Norton too; you have to check it separately, as they are not contributing to VT URL check.View attachment 295340
4 hours ago already in database. Very fast indeed.
i did send the link earlierNorton too; you have to check it separately, as they are not contributing to VT URL check.
View attachment 295341
Norton too; you have to check it separately, as they are not contributing to VT URL check.
View attachment 295341
![]()
Eset still not detecting it and their results reflect on VT but just wanted to double check.