App Review This ransomware bypass every antivirus and removes antivirus

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Bot

AI-powered Bot
Apr 21, 2016
4,789
It's concerning to hear about ransomware bypassing antivirus software. Thanks for sharing the videos. Remember, it's crucial to keep your software updated and to use multi-layered security measures.
 

bazang

Level 12
Jul 3, 2024
551


The malware is private malware like Solaris. I don't tested Comodo because he is clearly cheater due to auto containment but I bypassed him before.

Very nice malware, testing, and videos.

Only fool's think that "I can find a default allow security solution that will prevent this sort of thing."

The only effective security is to never allow code to execute unless it is done after a capable person has vetted it properly. The vetting and approval of the code must be performed by a human. Not AI and not ML. And no allowing by reputation, signature, or other default allow mechanisms. In other words, no more pandering to "users who want to use stuff." But that is way too much for the world to handle.
 

cartaphilus

Level 12
Well-known
Mar 17, 2023
575
Wait so webroot actually stopped it?!!!! Coooool!!!!!!


First time ever! I am seeing webroot beat out every other hit hitter out there.

Did the malware use AI to check what AV is running and it saw Webroot so it decided that this must be a Honeypot and just killed itself? Because damn!!! Massive props to webroot. Recognition is given where it's warranted and honestly great job!
 

annaegorov

Level 2
Feb 6, 2018
73
Wait so webroot actually stopped it?!!!! Coooool!!!!!!


First time ever! I am seeing webroot beat out every other hit hitter out there.

Did the malware use AI to check what AV is running and it saw Webroot so it decided that this must be a Honeypot and just killed itself? Because damn!!! Massive props to webroot. Recognition is given where it's warranted and honestly great job!
Your goofing this guy right?
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,821
It is a nice example of a known attack vector described here:

This attack vector has been used in the wild for several years (Snatch ransomware in 2018). It requires high privileges so in Enterprises, the attack can be dangerous via lateral movement.
Currently, the AVs can use some ATP features, like the Microsoft Defender ASR rule "Block rebooting machine in Safe Mode (preview)", which can prevent such attacks.
 

Nikola Milanovic

Level 4
Verified
Oct 17, 2023
186


The malware is private malware like Solaris. I don't tested Comodo because he is clearly cheater due to auto containment but I bypassed him before.

1740838046745.png
We will see what Xcitium has to say about it
1740838071055.png
Human Expert Analysis is In Proggres
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top