App Review This ransomware bypass every antivirus and removes antivirus

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.


The malware is private malware like Solaris. I don't tested Comodo because he is clearly cheater due to auto containment but I bypassed him before.

Very nice malware, testing, and videos.

Only fool's think that "I can find a default allow security solution that will prevent this sort of thing."

The only effective security is to never allow code to execute unless it is done after a capable person has vetted it properly. The vetting and approval of the code must be performed by a human. Not AI and not ML. And no allowing by reputation, signature, or other default allow mechanisms. In other words, no more pandering to "users who want to use stuff." But that is way too much for the world to handle.
 
Wait so webroot actually stopped it?!!!! Coooool!!!!!!


First time ever! I am seeing webroot beat out every other hit hitter out there.

Did the malware use AI to check what AV is running and it saw Webroot so it decided that this must be a Honeypot and just killed itself? Because damn!!! Massive props to webroot. Recognition is given where it's warranted and honestly great job!
 
Wait so webroot actually stopped it?!!!! Coooool!!!!!!


First time ever! I am seeing webroot beat out every other hit hitter out there.

Did the malware use AI to check what AV is running and it saw Webroot so it decided that this must be a Honeypot and just killed itself? Because damn!!! Massive props to webroot. Recognition is given where it's warranted and honestly great job!
Your goofing this guy right?
 
It is a nice example of a known attack vector described here:

This attack vector has been used in the wild for several years (Snatch ransomware in 2018). It requires high privileges so in Enterprises, the attack can be dangerous via lateral movement.
Currently, the AVs can use some ATP features, like the Microsoft Defender ASR rule "Block rebooting machine in Safe Mode (preview)", which can prevent such attacks.
 


The malware is private malware like Solaris. I don't tested Comodo because he is clearly cheater due to auto containment but I bypassed him before.

1740838046745.png
We will see what Xcitium has to say about it
1740838071055.png
Human Expert Analysis is In Proggres
 
Last edited by a moderator: