Huorong Internet Security Stable (heavily tweaked) - April 2021 report

Der.Reisende

Level 45
Thread author
Honorary Member
Top Poster
Content Creator
Malware Hunter
Dec 27, 2014
3,409
40,409
4,399
Germany
www.flickr.com
April 2021​
Samples Pack​
Static Detection​
Dynamic Detection​
Total Detection​
System files encrypted​
2nd_opinion scanners result
(NPE + HMP)
inactive remnants will also lead to "infected"​
System final status
br = before reboot
ar = after reboot
within SD environment
reboot = logout​
01/04/2021​
5​
2​
1​
3​
no
clean
protected
02/04/2021​
5​
2​
3​
5​
no / yes, bonus test ignoring custom rules
clean
clean / infected (without custom rules)
03/04/2021​
1​
0​
1​
1​
no
infected
not clean
04/04/2021​
5​
3​
2​
5​
no
clean
clean
06/04/2021​
15​
7​
4​
11​
rather wiped
infected
infected
06/04/2021​
4​
1​
0​
1​
yes, 4, on Desktop
infected
infected
07/04/2021​
3​
0​
2​
2​
no
clean
protected
08/04/2021​
1​
0​
0​
0​
no
clean
protected
09/04/2021
(w/o cust. rules)​
8​
1​
4​
5​
no
infected
infected
15/04/2021
(w/o cust. rules)​
3​
1​
2​
3​
no / yes, bonus test (some files only, user folders, D:// safe)
infected
clean / infected (bonus dynamic test)
17/04/2021 (w/o cust. rules)
5​
2​
3​
5​
no
clean
infected / not clean
18/04/2021 (w/o cust. rules)​
2​
1​
1​
2​
no / yes, bonus test
clean / infected (bonus dynamic test)
protected / infected (bonus dynamic test)
19/04/2021 (w/o cust. rules)​
2​
2​
2​
2​
no
clean
clean / protected (bonus dynamic test)
20/04/2021​
7​
3​
3​
6​
no
infected
infected
23/04/2021​
10​
3​
2​
5​
no
infected
infected
25/04/2021​
10​
7​
3​
10​
no
infected
infected / not clean



Action on threat detection: clean (instead of ask)
Behavior Based Detection: Enable Ransomware Trapping
HIPS: File / Registry / Sensitive action: all possible rules enabled (default action is still "ask")
HIPS: Enable Network Access Control (kinda outbound Firewall, colour indicator green and orange - safe or not)
HIPS: Webcam Protection: uncheck "Permit programs with a valid digital signature" and "Permit system core programs"
Installation Detection: Automatically block recognized installations of unlisted softwares
Firewall: Lateral Movement Protection - Remote MMC and Remote WMI also on
Network Access Control on (=two-way Firewall)
Advanced: Enable custom rules
Imported custom rules shared by user JerryLin - v4.24_1 - Update - Huorong Internet Security (Stable)
 
Last edited: