Cerber ransomware can now detect virtual machines to prevent analysis

Handsome Recluse

Level 23
Verified
Top Poster
Well-known
Nov 17, 2016
1,242
Tough because my Macrium Images are on 2 local drives, and 2 separate detached, external drives.

IF they can touch those 2, they know magic.
abra[1].gif
No. Psychic. Quantum Entanglement teleportation. No one's safe.
abra[1].gif
 

Peter2150

Level 7
Verified
Oct 24, 2015
280
Bunch of questions. Mods forgive but some just requiring mentioning other products. If this is bad let me know.

On the macrium question. Some of the ransomware I've played with will in fact encrypt the images and if that happens bye bye

I wrestled with how to protect my 2nd and 3rd internal drives. Many of the ransomware programs don't protect them. That is a fatal flaw. I finally settled on Pumpernickel(FIDES) as the solution. It locks changing files on the disks, but I can specifiy that certain programs can make changes. Cheap, only $13US. Big down side is it's only a driver controled by an ini file. EVERYTHING is manual. But it works.

That protects the images, so now the c: drive is a restore issue only.

As to what Rollback will do, I don't know. I won't use it as I don't trust either the software or the company. I don't like what it does to the imaging situation either. I don't believe there is any way to put Rollback on key. On there similiar in concept program is Raxco's Instant Recovery. While it could be used if your images are protected. It would be very unwieldy and time consuming.

What about all these new Anti Ransomware programs. To me a big Blah. By the time any of them detect anything YOU ARE INFECTED!!!. If that happens the smartest move would be to have an image to restore, in which case the use of these programs and is to me at least a waste of money
 
  • Like
Reactions: _CyberGhosT_

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,150
Solar- detection really depends on what you are checking- For instance if you check the original malware which is a vbs script you may get few detections as this is not in itself malicious, but will download the payload. But if you check the actual payload (like in the 4th one you indicated) things are different. And about the dll's (2 and 3)- not all dropped dll's will be actually malicious.

So the most important detections would be 3 and 4.
 

Solarquest

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Cruelsister, thanks.

Bte, I just checked the 4 Sha Trend provided (and stated that they were detecting).
I think it's strange to see how some are not detected or Emsisoft is not showing in the 3rd one.

In general, not related to the Cerber above, I think it's weird to see AV detect samples by the URL they try to connect to but then miss the executable/payload.
 

Game Of Thrones

Level 5
Verified
Well-known
Jun 5, 2014
220
trend gets them on execution most of the time. even in virtual machines, i believe trend micro is not doing good at advertisement only the pro people know them, IMO their software is sometimes way better than some other software that the users most of the time use. they have bad things like false positive which is getting lower in every version. i'm testing their version 12 of software they enabled machine learning in this version for home products.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top