- Oct 13, 2019
- 784
@Anthony Qian first mentioned something along these lines and I started doing a little testing of new Emotet/Snake samples.... In the past, zero-day detections usually come from HEUR/APC (Avira cloud). But recently, F-Secure is detecting them using "!fsmind" signatures, like "Trojan:W32/Generic.abch!fsmind" or "Backdoor:W32/Androm!fsmind_tc"
These appear to be unique to F-Secure and my best guess is that "fsmind" is the new replacement for "fso"/F-Secure Online. Is F-Secure no longer using Avira Protection Cloud? Anyone seen APC detections recently?
(I did confirm that 'fsmind' detections do not trigger when offline so it's definitely some sort of cloud based detection).
As an aside: VirusTotal's F-Secure is offline-only, these samples show up as clean on VT but the actual F-Secure product detects it statically.
These appear to be unique to F-Secure and my best guess is that "fsmind" is the new replacement for "fso"/F-Secure Online. Is F-Secure no longer using Avira Protection Cloud? Anyone seen APC detections recently?
(I did confirm that 'fsmind' detections do not trigger when offline so it's definitely some sort of cloud based detection).
As an aside: VirusTotal's F-Secure is offline-only, these samples show up as clean on VT but the actual F-Secure product detects it statically.