App Review This ransomware bypass every antivirus and removes antivirus

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Szellem

Level 10
Verified
Well-known
Apr 15, 2020
458


The malware is private malware like Solaris. I don't tested Comodo because he is clearly cheater due to auto containment but I bypassed him before.

This is tough!
You can kill the AVs pretty well. Unfortunately, AVs are a false sense of security. A lot depends on the User. Reading AndyFull, I prefer free Defender plus ASR rules.
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,821
I prefer free Defender plus ASR rules.

ASR rules are OK, they can "raise the bar" for many attackers. :)
This malware can probably be prevented by Comodo Firewall (@cruelsister settings), Kaspersky (@harlan4096 settings), Avast with Hardened mode, etc.
In the home environment, also SmartScreen file reputation can be quite efficient.
However, no reasonable protection can stop the highly motivated attacker.
 

Szellem

Level 10
Verified
Well-known
Apr 15, 2020
458
ASR rules are OK, they can "raise the bar" for many attackers. :)
This malware can probably be prevented by Comodo Firewall (@cruelsister settings), Kaspersky (@harlan4096 settings), Avast with Hardened mode, etc.
In the home environment, also SmartScreen file reputation can be quite efficient.
However, no reasonable protection can stop the highly motivated attacker.
Which Kaspersky setup do you mean that harlan4096 made?
Does the ASR Rule you posted also block user initiated safe mode?
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,821
It would be interesting to see if it could bypass the WDAC ISG (like in WHHLight).

The initial malware can be most probably blocked by WDAC ISG before execution (due to the low prevalence). I can test it if someone would like to share the sample.
The ransomware dropped by the initial malware can be blocked by WDAC in Safe Mode if the sample is executed from a non-whitelisted location. The initial malware blocks the Internet connection before restarting in Safe Mode, so ISG cannot check the positive reputation and WDAC blocks the file.
 
Last edited:

harlan4096

Super Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
9,039
Which Kaspersky setup do you mean that harlan4096 made?
1740860764121.png
 
Last edited:

Szellem

Level 10
Verified
Well-known
Apr 15, 2020
458
The initial malware can be most probably blocked by WDAC ISG before execution (due to the low prevalence). I can test it if someone would like to share the sample.
The ransomware dropped by the initial malware can be blocked by WDAC in Safe Mode if the sample is executed from a non-whitelisted location. The initial malware blocks the Internet connection before restarting in Safe Mode, so ISG cannot check the positive reputation and WDAC blocks the file.
Andy! It would be really nice if you could test these samples as you write.
 

Szellem

Level 10
Verified
Well-known
Apr 15, 2020
458
I think I proved one malware enough to destory malware but that's rarely happens. I will test antiviruses aganist fully zero day harmful ip address. That would be too interesting than this because it's not only one malware it's too many urls.
I think you've little bit misunderstand. Your evidence is fine.

What you should look at is what Andy described, in this case what's happening. And also how the Defender behaves in this situation.
 

XylentAntivirus

Level 3
Thread author
Verified
May 9, 2024
128
I think you little bit misunderstand. Your proof is fine.
What you should look at is what Andy also described, in which case this does not happen. Also, how Defender behaves in this situation.
It detects by cloud right now probably but it didn't got deleted because Andy explanation is correct and we need use another method like Defender remover. But can't detect ransomware payload for some reason (I don't know is he going to detect final payload right now but when I tested in past it didn't get detected.).
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top