App Review Kaspersky Security Cloud Free vs Ransominator (default settings)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

fabiobr

Level 12
Verified
Top Poster
Well-known
Mar 28, 2019
569
Thanks to application control custom rules, document files were protected in my test.

Advanced disinfection starts, restart the system and all things rolled back.

Cloud Detection:

2020-04-26 (5).png
 
Last edited:

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
784
Same as SEP default will be blocked by app control / system lockdown
For the purposes of this test, I don't consider an application control feature to be the same as detection and blocking of this attack.

Yes, application whitelisting and reputation control are part of your layered protection, but this is specifically intended to be a test of a ransomware encrypting mechanism. Blocking the POC from running in the first place is not successfully identifying malicious behavior the way we want our dynamic behavior blockers to do so.
 

Vitali Ortzi

Level 24
Verified
Top Poster
Well-known
Dec 12, 2016
1,324
For the purposes of this test, I don't consider an application control feature to be the same as detection and blocking of this attack.

Yes, application whitelisting and reputation control are part of your layered protection, but this is specifically intended to be a test of a ransomware encrypting mechanism. Blocking the POC from running in the first place is not successfully identifying malicious behavior the way we want our dynamic behavior blockers to do so.
well Sonar/bloodhound always sucked
 
  • Like
Reactions: stefanos

Brahman

Level 18
Verified
Top Poster
Well-known
Aug 22, 2013
884
An average user need not get into panic mode on seeing these kind of videos because the file will get blocked by Kaspersky before it reaches an average user. But at the same time it also reminds us to have a locked down state in our systems while opening attachments or unknown files.
 

MacDefender

Level 16
Verified
Top Poster
Oct 13, 2019
784
An average user need not get into panic mode on seeing these kind of videos because the file will get blocked by Kaspersky before it reaches an average user. But at the same time it also reminds us to have a locked down state in our systems while opening attachments or unknown files.
I’ll go one step further and say to simply not take risks that you don’t have to take! We can feel warm and cozy that we have advanced and well tested AV software and layers of protection but it’s easy to become overconfident. Zero day exploits exist. Modern exploits have demonstrated attackers know how to chain a bunch of exploits together to defeat layers of security.
 

Xjoker

Level 1
Feb 19, 2020
38
This sample isn't special but ones like fun.bat/exe test in the hub did surprise me and some signed sample i tested
But don't think you are safe i few samples i tested bypassed wise vector

The same can be said for all the antiviruses out there. You can bypass any of them (except comodo IMHO). But in general WV has a very very good detection rate and a powerful behavior blocker!
 

Xjoker

Level 1
Feb 19, 2020
38

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
In my opinion AVAST can be bypassed even in HM.
yes it can but when you combine it with syshardener with proper settings, it would be very hard to bypass HM aggressive (not moderate mode)
Hardened mode only support .exe files so other extensions can easily bypass it. Syshardener will block most scripts and vectors that can bypass HM
I have used and tested avast for 3 years. There was only 1 bypass, which was a PUP
 

Xjoker

Level 1
Feb 19, 2020
38
yes it can but when you combine it with syshardener with proper settings, it would be very hard to bypass HM aggressive (not moderate mode)
Hardened mode only support .exe files so other extensions can easily bypass it. Syshardener will block most scripts and vectors that can bypass HM
I have used and tested avast for 3 years. There was only 1 bypass, which was a PUP

Totally agree with you! In case you add syshardener it is almost impossible to bypass it, but it's the same for the other antiviruses as well.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Totally agree with you! In case you add syshardener it is almost impossible to bypass it, but it's the same for the other antiviruses as well.
I agree. However, there are few AVs which offer something like HM, especially for free.
Kaspersky has TAM
Some AV have HIPS, but this generates too many prompts, does not automatically allow if the file is safe (n)
Windows has Smartscreen, which works almost exactly the same as HM but a file must be downloaded from a web browser or Smartscreen won't check it
Comodo has autosandbox, reputation-based
.......
 

Xjoker

Level 1
Feb 19, 2020
38
I agree. However, there are few AVs which offer something like HM, especially for free.
Kaspersky has TAM
Some AV have HIPS, but this generates too many prompts, does not automatically allow if the file is safe (n)
Windows has Smartscreen, which works almost exactly the same as HM but a file must be downloaded from a web browser or Smartscreen won't check it
Comodo has autosandbox, reputation-based
.......

Agree about the HM in AVAST, it must be the only av offering such an option for free! As far as I know Kaspersky 2021 won't have TAM anymore. :)
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top