KnowBe4’s Ransomware Simulator "RanSim"

Status
Not open for further replies.

vinylmeister

Level 2
Thread author
Verified
Jan 29, 2015
96

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,141
Hot discussions now at Wilders Security Forums and SpiceWorks Community

RanSim Ransomware Simulator test and discussion thread

"RanSim"... A Ransomware Simulator ...


I tried it and the result is

8/10 - G Data AV 2017 failed both Streamer and InsideCryptor

9/10 - HMPA failed Streamer only

0/10 - RansomFree failed ALL!!

0/10 - BD AntiRansomware Tool Free failed ALL!!

7/10 - Kaspersky Anti-Ransomware Tool for Business failed for Streamer, StrongCryptoNet and WeakCryptor

10/10 - CFW's HIPs alerted me of the 10 ransomwares. Can consider blocked if I block them

10/10 - AppCheck AntiRansom Free passed ALL!!

0/10 - ThreatFire 4.7 failed ALL!! (Tested by others)


From the above discussions it also seems Avast in 'Hardened Mode' and KIS passed ALL the 10 tests!


There's another free anti-ransomware defense testing tool by WatchPoint. You can read and download here

Tip of the Week – A Free Tool For Testing Anti-Ransomware Defenses
 
Last edited:

erreale

Level 9
Verified
Content Creator
Malware Hunter
Well-known
Oct 22, 2016
409
Hi everyone, I have tested Emsisoft IS and Malwarebytes 3.0. Emsi exceeded the test with 10/10.
By malwarebytes no allert. o_O
 

Attachments

  • RanSim.jpg
    RanSim.jpg
    599.3 KB · Views: 596

HarborFront

Level 72
Verified
Top Poster
Content Creator
Oct 9, 2016
6,141
Ok, test results updated. Tested with Ransim v1.0.2.2

8/10 - G Data AV 2017 failed both Streamer and InsideCryptor

9/10 - HMPA failed Streamer only

0/10 - RansomFree failed ALL!!

0/10 - BD AntiRansomware Tool Free failed ALL!!

7/10 - Kaspersky Anti-Ransomware Tool for Business failed for Streamer, StrongCryptoNet and WeakCryptor

10/10 - CFW's HIPs alerted me of the 10 ransomwares. Can consider blocked if I block them

10/10 - AppCheck AntiRansom Free passed ALL!!

0/10 - ThreatFire 4.7 failed ALL!! (Tested by @Av Gurus)

10/10 - VoodooShield (Tested by @XxX Legolas XxX)

10/10 - EAM (Tested by @Fabian Wosar)

10/10 - EIS (Tested by @Xtwillight)

10/10 - Vipre Business (Tested by @In2an3_PpG)

10/10 - NoVirusThanks EXE Radar Pro (Tested by @Davidov)

10/10 - Norton Security/MBAM (Tested at Wilders Security Forums) RanSim Ransomware Simulator test and discussion thread


I believe as time goes by more antiransom software will pass the test. And RanSim, hopefully, will come out with a new release and there goes another round of tests again

:D
 
Last edited:

mecanicogolf

Level 1
Jan 7, 2015
5
Yes. Malwarebytes picked them all up with no problem, Though I think that´s good, they are still claiming that you need no AV with this either. What this program DOES fail is the EICAR test!
 

silversurfer

Super Moderator
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,112

Chris Hartwig

New Member
Jan 12, 2017
1
notice that Zepto is not one of the test variants being used by RanSim, Zepto goes straight after network shares and only CryptoStopper Server from WatchPoint could protect you from that.

The way ransim works...and I use "works" loosely is that it creates a folder with dummy data and then launches a series of attacks against that honey pot folder. In my testing only 1 test actually ran and I've done some digging around on spiceworks and found other users have reported the same results.

If you want a ransomware tester...check out WatchPoint's powershell simulator. It's the real deal.

Tip of the Week – A Free Tool For Testing Anti-Ransomware Defenses
 

Korea

Level 1
Verified
Jan 11, 2017
20
ESET developer's answer.
It's an innocuous application that doesn't tell anything about detection and protection capabilities of ESET products. They test behavior blocking without distinguishing between malicious and benign applications. However, ESET does not only monitor the system and processes for suspicious behavior, it also scans memory for malware-like code. This also enables ESET not to warn about benign applications. Needless to say that there are many ways how the encryption works so the simulator may theoretically help malware authors to avoid techniques used by the simulator.

In a nutshell, programs that pass the simulator tests may be more prone to encryption by ransomware than ESET.

Just ran RanSim = Detection failed
 
Last edited:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top