App Review Shadowra's Big Comparative : Episode 2 - Paid Antivirus

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Shadowra

Khushal

Level 2
Apr 4, 2024
91
Can you send me by pm the sample if still not detected?
i asked kaspersky to detect it given that it seemed it was missed. i got a response that signature will be added. The analyst added that this is an injector payload of lumma and does not work on VM as it is VM aware. Plus the dropper doesn't exist with it. Hence it is harmless. Kaspersky will block it 100% proactively if it does any damage on a real system.
 
Last edited:

Captain Awesome

Level 25
Verified
Top Poster
Well-known
May 7, 2016
1,481
@ zidong I am not fan of anyone. Kaspersky is best in their field and it's a fact. Nobody can disagree with that. I am a user of this company I paid for their services. You can called me your so called"fan" of K7 of my 🇮🇳country.. you can say that..keep a mirror in front of you.🪞 Good day 🙏
 
Last edited:

Khushal

Level 2
Apr 4, 2024
91
Can you send me by pm the sample if still not detected?
I want to add more if u see the VT relations of the malicious C2 domain.
U will find that the domain and the two .NET droppers were already detected by Kaspersky automatically before this detection but still one more executable is undetected.
home(.)eleventh11pt(.)top
detected msi droppers
a0249644c8ecc612b57d5a9165a3e2e2c350b9f37b6ebd9a536e6d16a31ab861
812ac4b4e700471e5f7d180d21725f4f57b6c1abb20727c14491f8a5e5780b68
undetected final payload dependent on initial dropper
cdb4d1777a955ec4358093e17788ffe13d74d78062c7372c13e7ff40905de8b5

I request anyone to send the above sample to Kaspersky (just the hash) for their own peace of mind (love for 100% detections)
 

cofer123

Level 3
Sep 7, 2021
149
i asked kaspersky to detect it given that it seemed it was missed. i got a response that signature will be added. The analyst added that this is an injector payload of lumma and does not work on VM as it is VM aware. Plus the dropper doesn't exist with it. Hence it is harmless. Kaspersky will block it 100% proactively if it does any damage on a real system.
So if I understand it correctly, had @Shadowra tested this sample outside of a VM it would have actually executed but then Kaspersky would have blocked it?
 

Khushal

Level 2
Apr 4, 2024
91
So if I understand it correctly, had @Shadowra tested this sample outside of a VM it would have actually executed but then Kaspersky would have blocked it?
In a real world scenario u wouldn't have received the final undetected payload rather that msil dropper. Most probably someone a researcher maybe extracted those two payloads after running the droppers on A VM just to check what VT has to say about them.
 

silversurfer

Super Moderator
Verified
Top Poster
Staff Member
Malware Hunter
Aug 17, 2014
11,299
Surprised me that the topic isn't Comodo even this time as here we see another forum thread where someone is unable for self-control what shouldn't said nor written.

For better understanding, just quoted a part of the Forum Rules:
The guidelines and rules listed below explain what behavior is expected of you and what behavior you can expect from other community members. Note that the following guidelines are not exhaustive, and may not address all manner of offensive behavior. As such, the forum moderators shall have full discretion to address any behavior that they feel is inappropriate.

Your access to these forums is a ‘privilege’, and not a ‘right’. We reserve the right to suspend your access to these forums at any time for reasons that include but are not necessarily limited to, your failure to abide by these guidelines.
  1. Respect other members. Treat others with kindness and respect, and avoid personal attacks or insults.
  2. No spam or self-promotion. Do not post spam, self-promotional content, or irrelevant links.
  3. No illegal or malicious content. Do not post or link to illegal or malicious content, including software cracks, malware, or phishing scams.
  4. No piracy. Do not request or share pirated software or content.
  5. Stay on topic. Keep discussions relevant to the forum in which they are posted.
  6. Follow the instructions of moderators. Moderators are here to help keep the forums running smoothly and enforce these rules. If a moderator asks you to stop doing something or to follow a specific rule, please comply.
  7. Report any violations of these rules. If you see someone breaking these rules, please use the "Report" button to bring it to the attention of the moderators.
 

Shadowra

Level 37
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
Sep 2, 2021
2,674
It's important to remember that the ratings are always at the time I'm filming, and results can always change, given the work of antivirus laboratories.

Note that I submit ALL samples once the test is complete. So it's only logical that you should see the threats detected.

@harlan4096 : thanks for reminding me about TCPViewer, something I always forget to use... It will be put on Part 3 and subsequent tests :)

To the other members: please be respectful with everyone, we love testing, antivirus, but please no hateful or aggressive messages, I don't want the topic to become Hunger Games ;)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top