Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
I asked them if they used Wireshark or PE Studio, they replied:I don’t understand what they are trying to say. Are they refusing to just analyse any cracks in general, or they just know it’s harmless and think you’re asking them to add detection because it is a crack…?
Hello,
This exact request is not covered by our standard support policy.
Thank you for your inquiry to Kaspersky.
the latterI don’t understand what they are trying to say. Are they refusing to just analyse any cracks in general, or they just know it’s harmless and think you’re asking them to add detection because it is a crack…?
Seems like they already knew the file. It's not the first time they've seen it. So I don't think they are trolling you, they just knew it was safe, perhaps (not perhaps, definitely) they keep some analysis report. They just looked up the analysis. I can imagine it's a very detailed one.@Trident Do you reckon Kaspersky might be trolling me? I sent them another sample (not adobe crack) and within 2 minutes they said it was clean. You seem very knowledgeable, so let me put it this way: Do you believe that within 2 minutes, using their inhouse tools - whatever they are - they can tell if a file is malicious or not?
Kaspersky is powered by KSN. You submit it or not, other users who got a copy of that file and enabled sharing will transmit the infos necessary to analyze that in Kaspersky Labs. They already know it thru their database.@Trident Do you reckon Kaspersky might be trolling me? I sent them another sample (not adobe crack) and within 2 minutes they said it was clean. You seem very knowledgeable, so let me put it this way: Do you believe that within 2 minutes, using their inhouse tools - whatever they are - they can tell if a file is malicious or not?
Seems like they already knew the file. It's not the first time they've seen it. So I don't think they are trolling you, they just knew it was safe, perhaps (not perhaps, definitely) they keep some analysis report. They just looked up the analysis. I can imagine it's a very detailed one.
So on average, how long does it take for vendors like Kaspersky to actually thoroughly analyze samples for malicious activity the first time they're ever submitted? Days? Weeks? Using whatever inhouse tools they useKaspersky is powered by KSN. You submit it or not, other users who got a copy of that file and enabled sharing will transmit the infos necessary to analyze that in Kaspersky Labs. They already know it thru their database.
Submitting it is a manual way, threat sharing is another automated way.
These companies receive millions of samples daily, majority of the analysis is automated. I can't say how long it takes for Kaspesky, but for Avast. it is usually around 10 minutes and they start blocking the sample as well as all C&Cs. For some samples, the automated analysis will be inconclusive. These will be enqueued. When this happens, it could take most likely hours to a day before the sample is analysed by a human.So on average, how long does it take for vendors like Kaspersky to actually thoroughly analyze samples for malicious activity the first time they're ever submitted? Days? Weeks? Using whatever inhouse tools they use
So do they use machine learning for automated analysis? And do the machine learning tools use stuff like deep packet analysis and soemthing that WireShark would show you?These companies receive millions of samples daily, majority of the analysis is automated. I can't say how long it takes for Kaspesky, but for Avast. it is usually around 10 minutes and they start blocking the sample as well as all C&Cs. For some samples, the automated analysis will be inconclusive. These will be enqueued. When this happens, it could take most likely hours to a day before the sample is analysed by a human.
They do not use WireShark, they use something like Snort or Suricata with custom rules, some of these rules could be developed by inhouse specialists, others are likely purchased. They use everything available, static, dynamic analysis, AI, yara rules and so on, domain analysis and whois on all connections. Though it will vary from vendor to vendor, I would assume no stone remains unturned when they analyse a sample.So do they use machine learning for automated analysis? And do the machine learning tools use stuff like deep packet analysis and soemthing that WireShark would show you?
How come Kaspersky failed to detect a malware? The VirusTotal page is clean for Kaspersky VirusTotalThey do not use WireShark, they use something like Snort or Suricata with custom rules, some of these rules could be developed by inhouse specialists, others are likely purchased. They use everything available, static, dynamic analysis, AI, yara rules and so on, domain analysis and whois on all connections. Though it will vary from vendor to vendor, I would assume no stone remains unturned when they analyse a sample.
How come Kaspersky failed to detect a malware? The VirusTotal page is clean for Kaspersky VirusTotal
Of course, you're right. But in conclusion, if I submit sth for re-analysis and they say it's clean, then is it definitely clean?You'll have to ask Kaspersky. I am not a Kaspersky representative to be held liable for their misses. As I said in my first post, Kaspersky is not some sort of a miracle. It's software like any other.
It has been confirmed now by humans that every day from 9 to 5 (or whatever) go to work and deal with malware analysis. Some of them probably have 5-10 years + experience in this field. So if they say the file is clean, then it is.Of course, you're right. But in conclusion, if I submit sth for re-analysis and they say it's clean, then is it definitely clean?
For future reference, how long should I run WireShark when looking for malicious network traffic? Would 5 minutes be enough or do i have to do it for hours?It has been confirmed now by humans that every day from 9 to 5 (or whatever) go to work and deal with malware analysis. Some of them probably have 5-10 years + experience in this field. So if they say the file is clean, then it is.
You will have to do as long as the process in question is running. Usually 5 minutes will be enough to reveal the malicious behaviour, attackers don't wanna wait and dwell all day, because at one point the malware may be detected. So I would say 5 minutes are enough, but it depends on the situation.For future reference, how long should I run WireShark when looking for malicious network traffic? Would 5 minutes be enough or do i have to do it for hours?
How would I evade the payload postpone logic on a physical host? As you said they might have logic to delay the payload by hours or days or even weeks on purposeYou will have to do as long as the process in question is running. Usually 5 minutes will be enough to reveal the malicious behaviour, attackers don't wanna wait and dwell all day, because at one point the malware may be detected. So I would say 5 minutes are enough, but it depends on the situation.
Short answer: you cannot. Whatever the programmer has written, that's what the malware is doing. That's how programming works, whatever you write, the system does. After the software is compiled, only specialised tools (which are not available for the general public) can to an extent, alter the behaviour by managing the CPU. You as a user cannot.How would I evade the payload postpone logic on a physical host? As you said they might have logic to delay the payload by hours or days or even weeks on purpose
You're very knowledgeable. Are you a programmer, or a cybersecurity IT guy?Short answer: you cannot. Whatever the programmer has written, that's what the malware is doing. That's how programming works, whatever you write, the system does. After the software is compiled, only specialised tools (which are not available for the general public) can to an extent, alter the behaviour by managing the CPU. You as a user cannot.
I am both. Most IT security guys are developers too.You're very knowledgeable. Are you a programmer, or a cybersecurity IT guy?
Members who viewed this thread in the last 5 minutes