Are you sure this is not fake? author does not show the contents of encrypted files
bat to exe - and rename files extensions
Loll indeed! That is one of my pet peeves.
I really respected the responses I got back from Fabian (Emsisoft), F-Secure, and WiseVector when we talked about this 7zip exploit.
GREAT response: WiseVector:
(paraphrased because the communication was private)
We've tuned our product to detect and stop some in-the-wild attacks that use WinRAR in a similar fashion. We didn't detect this one because it operates specifically within a test folder within My Documents. Our product is tuned to expect that to be legitimate behavior.
However, knowing that Kaspersky can block this attack, we will see if we can do better.
Acceptable/Respectable responses:
F-Secure:
Thanks also for your valuable inputs with the 7-zip example. Those techniques are always considered in our detection iterations. However, we need to take into cognizance the legitimate use cases for this application. Aggressively blocking software with ransomware-like behavior without other checks will cause lots of false positives which will significantly impact the usability of our products. In addition, there are traces of the password used to archive the files which may be easily recovered by looking into event logs or reversing the malware itself.
Emsisoft in other thread, paraphrased as "We consider once ransomware makes it onto a device, it can already be compromised in many ways. What you're seeing is reflective of the shift in focus to preventing host compromise as opposed to behavior blocking a malicious binary already on-host".
Video - Emsisoft Anti Malware (default) vs Ransominator
I don't mind if a vendor's choice is to explain why they're not taking any action for this proof of concept. I think those are good answers from all 3 vendors for their justification.
The most disappointing answers were the ones from ESET which said their product would react to real ransomware, this is not real ransomware, and if you write real ransomware, that's illegal/unethical.