App Review Malware Magic

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
cruelsister

I can’t reliably determine the video’s content or verify its claims from the embedded link alone.

Please provide the video title, transcript, or the specific security claim you want assessed. For malware-related claims, include the relevant file or URL and any available scan results; avoid downloading unknown files just to investigate them.
 
  • Like
Reactions: Jack
Hello cruel! This test was default settings or your recommended settings?
Settings would not matter for Magic to occur. Being as vague as I possibly can be- 2 forms of the same malware were used in the video. The first file run is like a cabinet you can buy at any store; the second is like the cabinet that makes a person disappear.
 
old magic
"black&white"
 
If I understood this video correctly, one EXE sample is auto-contained by CF (as expected), but the second is not.
If the second sample (Magic.exe) is properly signed by Microsoft, it should not be auto-contained by CF.
In this video, the Magic file is an outdated (renamed) version of MsMpEng.exe (Microsoft Defender engine more than 8 years old), which is exploited to run ransomware.
In older attacks, the exploitation of MsMpEng LOLBin was related to DLL hijacking.
Currently, this attack should be blocked by Microsoft Defender with the enabled ASR rule "Block use of copied or impersonated system tools".
So both samples can be dismantled for sure by the combined/tweaked protection of MD + CF, even if the exploit would not be blocked by CF and MD.

Post updated.
 
Last edited:

You may also like...