- Aug 7, 2016
- 228
Cerber version 4.1.1!
Last edited by a moderator:
UAC says that about CMD It's an original commandline app used by the ransomware.Probably it is not the first time , but I notice only now that UAC says that the verified publisher is MS
Thank you for sharing
Well, how it should work then? It does its job.Anyway it can confuse inexperienced users
It's just a name of this executed fileThe smartscreen shows cerber.exe . Is that a name set by the reviewer or it is shipped really with its real name ?
It's just a name of this executed file
Yes, file name has nothing to do with that. This file is uknown and suspicious for the SmartScreen so it blocked that. But SmartScreen doesn't look at the name or something.Smartscreen would have blocked it even with another name ?
Thanks for the video review
Antivirus scan for a31eb55003834823679085184dbdc0946ffd0037567bd2c088d16e6e95b0d913 at 2016-11-04 06:38:25 UTC - VirusTotal
A remark :
At UAC prompt, "yes" was clicked => to show the behavior of the sample.
Yes, but I think the purpose of this current video is only to show us the malware in actionDon't you think it would be useful to click no sometimes to see if there are UAC exploit?
Yes, but I think the purpose of this current video is only to show us the malware in action
CyberSecurity GrujaRS likes to show us all the process, from begin, to endOk but we can all imagine it will encrypt everything . Thank you for the videos of course I appreciate