App Review Comodo FW bypass malware the sandbox (sandbox hips off + on) and voodooshield (autopilot)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Davidov

Level 10
Thread author
Verified
Well-known
Sep 9, 2012
470
No reaction from Comodo stops just voodooshield PC shutdown but after the restart the PC infikovano.Pc then behave strangely. Detection on VirusTotal 0.
I used Comodo sandbox Improved Setup + Factory Defaults voodooshield.
No reaction from Comodo stops just voodooshield PC shutdown but after the restart the PC infikovano.Pc then behave strangely. Detecting malware on VirusTotal 0. testing on a living tree in the sandbox did not want to run or did not show. What should I use when everything disappoints .-))

https://www.hybrid-analysis.com/sam...7bf2ce35b121b9a9de59c2b0d51?environmentId=100

Antivirus scan for 8930b9c8dbf95fcc8184254546b99c00971517bf2ce35b121b9a9de59c2b0d51 at 2016-10-22 19:40:00 UTC - VirusTotal


 
H

hjlbx

Proof that it's trusted malware, not bypass: http://i.imgur.com/l7f4eS9.png
Not sure about VoodooShield though.

Valkyrie isn't detecting it as malicious. A Clean Valkyrie detection does not mean it is automatically added to the COMODO Safe List. Plus, CIS does not use Valkyrie - it hasn't been integrated yet into CIS>

It isn't officially clean until manually inspected by a COMODO technician. Then the tech has to add the file to the Safe List database.

Look at the VT Scan report - COMODO reports it as undetected = Unknown\Unrecognized.

It should be auto-sandboxed.

It is not trusted... so it's a CIS bypass.
 
H

hjlbx

VT says it was checked a week ago, and that it is totally undetected. sounds like a contradiction. what's up with that?

What's so strange about that ?

There is such a thing as undetected malware for days, weeks, months, years... or never.

A script that will delete your entire disk drive can be used legitimately or maliciously - and no scan engine typically detects such a user created script as malicious.
 

vivid

Level 5
Verified
Dec 8, 2014
206
Valkyrie isn't detecting it as malicious. A Clean Valkyrie detection does not mean it is automatically added to the COMODO Safe List. Plus, CIS does not use Valkyrie - it hasn't been integrated yet into CIS>

It isn't officially clean until manually inspected by a COMODO technician. Then the tech has to add the file to the Safe List database.

Look at the VT Scan report - COMODO reports it as undetected = Unknown\Unrecognized.

It should be auto-sandboxed.

It is not trusted... so it's a CIS bypass.

1. There is a signature-level detection and a cloud-level detection.
2. I have used Valkyrie to check status. You can see that it is trusted in my picture.
3. CIS does not use Valkyrie. Rephrased: CIS does not auto-submit files for analysis to Valkyrie.
4. If a file is rated by human analyst in Valkyrie then a signature-level detection will be added automatically to CIS.
5. You can look at human analysis as a cloud verdict with CIS.
6. VirusTotal checks for signature-level detection. In no way you will know by using VirusTotal if there's a difference between unrecognized and trusted verdict.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top