16GB minimum is recommended 32 GBNever used VM before; I think it requires ample amount of RAM.
16GB minimum is recommended 32 GBNever used VM before; I think it requires ample amount of RAM.
A couple of hours ago, I performed full scan with MD.
It came out with a backdoor in Edge cache.
I recalled I was testing fresh samples from URLhaus and some of them triggered download which I have aborted immediately, but seems some code was residing in Edge cache.
I wondered, if MD could detect it by on-demand scan, why it did not detect it once it was downloaded in cache.
Looked for MOTW, it was absent; this explains why BAFS did not work.
Is there any method to make Edge add MOTW to files stored in cache?View attachment 288735
SmartScreen did not stop download; it was aborted manually.Such file artefacts were probably created by SmartScreen in Edge (download was prevented, so MotW is absent). They cannot be directly executed.
SmartScreen did not stop download; it was aborted manually.
SS did not react, either by blocking page load or blocking download; it only block download of simplewall installerIn this way, you did not test BASF and SmartScreen for downloads. You only tested the SmartScreen URL blocking of samples from the URLhaus website.
The URLs you tested were not used in the wild, so SmartScreen ignored them (even if the in-the-wild URL was blocked by SmartScreen).
SS did not react, either by blocking page load or blocking download ...
No; I stopped it manually.Did you let Edge fully download the files?
No; I stopped it manually.
SS, for example, stops simplewall installer from starting download, even before I intervene.