App Review SecureMyBit Deny VS 6 JavaScript malware + EXE analysis

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

tim one

Level 21
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
Thanks for the video.
Is SecureMyBit Deny able to detect if the JavaScript is malicious or is it just blocking all JavaScript from running?
From what I know SMB D blocks all scripts by default by disabling Windows Script Host, however if you want to run a trusted script you can easily disable Anti-Script protection from the GUI.
 

mekelek

Level 28
Verified
Well-known
Feb 24, 2017
1,661
I really don't want to be rude but did you really do a test of executing 5 js files while the tool clearly states it blocks every js file upon execution?
 

Windows_Security

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Mar 13, 2016
1,298
Accesso a Windows Script Host disabilitato (or something simular) sounds like "access to Windows Host disabled" :)
 
  • Like
Reactions: Der.Reisende

JM Safe

Level 39
Verified
Top Poster
Apr 12, 2015
2,882
Thanks for the great video @tim one ! A really good job :)
I really don't want to be rude but did you really do a test of executing 5 js files while the tool clearly states it blocks every js file upon execution?
A test is done to verify if a product really works as expected. In the video @tim one tested if the Anti-Script protection really works. So I don't see the sense of your question. Also Default-Deny of EXE files are tested.
 

tim one

Level 21
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
As we have already had the opportunity to see, tons of malware are using scripting techniques. The same techniques usually used to take advantage of the ability of Windows to automatically run the script. A script is a sequence of instructions that usually are used to automate a series of operations at operating system level. For those who know MS-DOS, the use of the script brings in a Windows environment, what in DOS you could do by using batch file (.BAT) by introducing a series of innovations, closely linked to the components of the operating system itself.

Windows Scripting Host is a sort of "interpreter" of the scripts that Microsoft has integrated within the system starting from Windows 98. Windows Scripting Host (WSH) allows you to boot directly from the Windows file VBS (Visual Basic Script) and JS (J-Script) by performing two important functions: first, WSH interprets the instructions contained in the script and allows you to handle any programming errors; in the second place, it offers the possibility, without having to install a real programming language, to interact with all the elements of Windows. Simple instructions allow, for example, engage with applications such as Word, Excel, Access, intervene on the registry, connecting to printers, creating network connections, and so on: all the operations, usually done manually, can be automated.

It is clear, then, what is the power of the script and how, inevitably, these could be used by malware.

IMO SMB Deny is a simple app that in its simplicity has its power to prevent a good part of the malware scripts just by using Windows settings.
 
Last edited:

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,148
Tim- bat files are still used today (actually someone just sent me a fresh one for an opinion); and for these SMB would be oblivious.

So one really should differentiate between scriptors that use cscript/wscript and those that do not.
 

tim one

Level 21
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
Tim- bat files are still used today (actually someone just sent me a fresh one for an opinion); and for these SMB would be oblivious.

So one really should differentiate between scriptors that use cscript/wscript and those that do not.
Hi cruelsister, when you open SMB D in the UI, if you move the mouse on "Anti-Script" button, you can see it blocks JS, VBS, JSE, etc. But not wscript or cscript. This depends on @JM Security development.
Thanks for the clarification.
 

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,148
Hi Tim! Disabling Windows Script Host on systems that rely on traditional methods of protection (such as an AV and/or BB) is a good thing. As those few who view my videos may have noticed (my last video as well as the forthcoming one), many products have issues with Scriptors.

The majority of scriptors currently in the Wild are vb and JScript based. SMB would be a nice compliment as it will stop these things cold; however with bat scripts, some self contained python malware and JAR (not Jscript) malware SMB will not really help.

Don't get me wrong! I compliment you for bringing up the need for basic Scriptor protection! However SMB over all is sub-optimal when compared to the Bliss of virtualization.
 

tim one

Level 21
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
Hi Tim! Disabling Windows Script Host on systems that rely on traditional methods of protection (such as an AV and/or BB) is a good thing. As those few who view my videos may have noticed (my last video as well as the forthcoming one), many products have issues with Scriptors.

The majority of scriptors currently in the Wild are vb and JScript based. SMB would be a nice compliment as it will stop these things cold; however with bat scripts, some self contained python malware and JAR (not Jscript) malware SMB will not really help.

Don't get me wrong! I compliment you for bringing up the need for basic Scriptor protection! However SMB over all is sub-optimal when compared to the Bliss of virtualization.
Yes, I also think SecureMyBit Deny can be a good addition to a security setup, but surely the developers could improve the product to improve protection scenarios.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top