Yes.Also blocked by SWH in WHHL?
Yes.Also blocked by SWH in WHHL?
Some informative really articles here. I'll have to set aside time to read them but sounds like even though bypassed by the remote admin, I'm reading your comments that in all these cases, at the end of it, Comodo sandboxes and contains the unknown payloads.In the case of CIS, the system could be compromised by the RemoteAdmin tool, but the multi-stage crypter is unknown (so far) in the Comodo Valkyrie Sandbox, so the malware would be auto-contained.
Some informative really articles here. I'll have to set aside time to read them but sounds like even though bypassed by the remote admin, I'm reading your comments that in all these cases, at the end of it, Comodo sandboxes and contains the unknown payloads.![]()
Just want to correct a few things from the above discussions:
1). regarding ScreenConnect, although having a valid signature in order for this malicious form to work (potentially steal) it MUST be able to connect out. I finally found a sample that was able to be installed (leaving the Kaspersky residue seen in the recent video), but when Outbound Connectivity is checked from within Comodo it can be seen that connections were blocked.
2). CF does indeed contain msiexec. View attachment 299142