Advice Request Way to Stop Files from Automatically Downloading?

Please provide comments and solutions that are helpful to the author of this topic.

always_forever

Level 1
Thread author
Jul 1, 2021
47
I have Voodoo Shield, Hard Configurator, and an AV.

Somehow, while working, an excel file automatically downloaded to my computer without my permission.

Is there a setting in Voodoo Shield or Hard Configurator to stop this from happening again?

Any insight appreciated!
 
  • Like
Reactions: [correlate]

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,119
I have Voodoo Shield, Hard Configurator, and an AV.

Somehow, while working, an excel file automatically downloaded to my computer without my permission.

Is there a setting in Voodoo Shield or Hard Configurator to stop this from happening again?

Any insight appreciated!

The problem of drive-by download without permission is usually related to HTML Smuggling. If you open a compromised or specially crafted web page (also specially crafted HTML attachment), then the embedded JavaScript can automatically do some things without your permission:
  1. Download a payload from a malicious URL to your disk.
  2. Drop a payload already embedded in the HTML attachment.
This can be prevented by blocking scripts in the web browser, but such a setting will also break many web pages.
Look for example here:

The attacker still cannot automatically execute the payload. In theory, the payload can be downloaded and executed without your permission, but this would require exploiting the web browser. Such exploits are quickly patched, so you probably will never see any of them.

Post edited.
I am not sure if the setting "Ask where to save..." can effectively solve the problem. The file can be probably saved without this alert to the default location.
 
Last edited:

silversurfer

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
I have Voodoo Shield, Hard Configurator, and an AV.

Somehow, while working, an excel file automatically downloaded to my computer without my permission.

Is there a setting in Voodoo Shield or Hard Configurator to stop this from happening again?

Any insight appreciated!

As already mentioned by @Andy Ful Browsers settings related to downloads doesn't help to prevent attacks like "drive-by-downloads", rather should be covered by AVs and software for same purpose like VoodooShield or others...

Most AVs monitoring all common attack vectors, but depends what AV are you using, you may want to tell?
VoodooShield has internal rules to block any known malicious activity, for more details you can ask developer @danb
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,119
I have Voodoo Shield, Hard Configurator, and an AV.
...

The AVs can hardly recognize the HTML Smuggling because it is done inside the web browser.
If you use H_C with Recommended_Settings (or more restrictive) then the dropped file cannot be normally executed. The execution will be possible only if the user is fooled by the attacker to intentionally bypass the protection.

I remember only one case of HTML Smuggling, while searching the specific & rare security information via Google. After opening one of the websites (looked suspicious to me), it dropped an EXE file to disk. That website did not mention anything about this file and any download, so it might be compromised. Microsoft Defender was silent. I checked the file and it was signed by the EV certificate and previously unknown on Virus Total. After checking, all AVs on Virus Total considered it clean.
Nothing indicated that the file could be malicious, except the HTML Smuggling.:(

Edit.
In many cases, the files dropped by HTML Smuggling will not be *.exe files but MS Office documents or other non-executable but weaponized files. These files can be a problem for AVs.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top