Question Will Kaspersky's network monitor catch suspicious activity in time?

Kaspersky
45 Replies 5,616 Views
Help answer the author's question with clear explanations and useful steps.
I don’t understand what they are trying to say. Are they refusing to just analyse any cracks in general, or they just know it’s harmless and think you’re asking them to add detection because it is a crack…?
I asked them if they used Wireshark or PE Studio, they replied:

Hello,

This exact request is not covered by our standard support policy.
Thank you for your inquiry to Kaspersky.
 
@Trident Do you reckon Kaspersky might be trolling me? I sent them another sample (not adobe crack) and within 2 minutes they said it was clean. You seem very knowledgeable, so let me put it this way: Do you believe that within 2 minutes, using their inhouse tools - whatever they are - they can tell if a file is malicious or not?
 
@Trident Do you reckon Kaspersky might be trolling me? I sent them another sample (not adobe crack) and within 2 minutes they said it was clean. You seem very knowledgeable, so let me put it this way: Do you believe that within 2 minutes, using their inhouse tools - whatever they are - they can tell if a file is malicious or not?
Seems like they already knew the file. It's not the first time they've seen it. So I don't think they are trolling you, they just knew it was safe, perhaps (not perhaps, definitely) they keep some analysis report. They just looked up the analysis. I can imagine it's a very detailed one.
 
@Trident Do you reckon Kaspersky might be trolling me? I sent them another sample (not adobe crack) and within 2 minutes they said it was clean. You seem very knowledgeable, so let me put it this way: Do you believe that within 2 minutes, using their inhouse tools - whatever they are - they can tell if a file is malicious or not?
Kaspersky is powered by KSN. You submit it or not, other users who got a copy of that file and enabled sharing will transmit the infos necessary to analyze that in Kaspersky Labs. They already know it thru their database.

Submitting it is a manual way, threat sharing is another automated way.
 
Seems like they already knew the file. It's not the first time they've seen it. So I don't think they are trolling you, they just knew it was safe, perhaps (not perhaps, definitely) they keep some analysis report. They just looked up the analysis. I can imagine it's a very detailed one.

Kaspersky is powered by KSN. You submit it or not, other users who got a copy of that file and enabled sharing will transmit the infos necessary to analyze that in Kaspersky Labs. They already know it thru their database.

Submitting it is a manual way, threat sharing is another automated way.
So on average, how long does it take for vendors like Kaspersky to actually thoroughly analyze samples for malicious activity the first time they're ever submitted? Days? Weeks? Using whatever inhouse tools they use
 
So on average, how long does it take for vendors like Kaspersky to actually thoroughly analyze samples for malicious activity the first time they're ever submitted? Days? Weeks? Using whatever inhouse tools they use
These companies receive millions of samples daily, majority of the analysis is automated. I can't say how long it takes for Kaspesky, but for Avast. it is usually around 10 minutes and they start blocking the sample as well as all C&Cs. For some samples, the automated analysis will be inconclusive. These will be enqueued. When this happens, it could take most likely hours to a day before the sample is analysed by a human.
 
These companies receive millions of samples daily, majority of the analysis is automated. I can't say how long it takes for Kaspesky, but for Avast. it is usually around 10 minutes and they start blocking the sample as well as all C&Cs. For some samples, the automated analysis will be inconclusive. These will be enqueued. When this happens, it could take most likely hours to a day before the sample is analysed by a human.
So do they use machine learning for automated analysis? And do the machine learning tools use stuff like deep packet analysis and soemthing that WireShark would show you?
 
So do they use machine learning for automated analysis? And do the machine learning tools use stuff like deep packet analysis and soemthing that WireShark would show you?
They do not use WireShark, they use something like Snort or Suricata with custom rules, some of these rules could be developed by inhouse specialists, others are likely purchased. They use everything available, static, dynamic analysis, AI, yara rules and so on, domain analysis and whois on all connections. Though it will vary from vendor to vendor, I would assume no stone remains unturned when they analyse a sample.
 
They do not use WireShark, they use something like Snort or Suricata with custom rules, some of these rules could be developed by inhouse specialists, others are likely purchased. They use everything available, static, dynamic analysis, AI, yara rules and so on, domain analysis and whois on all connections. Though it will vary from vendor to vendor, I would assume no stone remains unturned when they analyse a sample.
How come Kaspersky failed to detect a malware? The VirusTotal page is clean for Kaspersky VirusTotal
 
You'll have to ask Kaspersky. I am not a Kaspersky representative to be held liable for their misses. As I said in my first post, Kaspersky is not some sort of a miracle. It's software like any other.
Of course, you're right. But in conclusion, if I submit sth for re-analysis and they say it's clean, then is it definitely clean?
 
Of course, you're right. But in conclusion, if I submit sth for re-analysis and they say it's clean, then is it definitely clean?
It has been confirmed now by humans that every day from 9 to 5 (or whatever) go to work and deal with malware analysis. Some of them probably have 5-10 years + experience in this field. So if they say the file is clean, then it is.
 
It has been confirmed now by humans that every day from 9 to 5 (or whatever) go to work and deal with malware analysis. Some of them probably have 5-10 years + experience in this field. So if they say the file is clean, then it is.
For future reference, how long should I run WireShark when looking for malicious network traffic? Would 5 minutes be enough or do i have to do it for hours?
 
For future reference, how long should I run WireShark when looking for malicious network traffic? Would 5 minutes be enough or do i have to do it for hours?
You will have to do as long as the process in question is running. Usually 5 minutes will be enough to reveal the malicious behaviour, attackers don't wanna wait and dwell all day, because at one point the malware may be detected. So I would say 5 minutes are enough, but it depends on the situation.
 
You will have to do as long as the process in question is running. Usually 5 minutes will be enough to reveal the malicious behaviour, attackers don't wanna wait and dwell all day, because at one point the malware may be detected. So I would say 5 minutes are enough, but it depends on the situation.
How would I evade the payload postpone logic on a physical host? As you said they might have logic to delay the payload by hours or days or even weeks on purpose
 
How would I evade the payload postpone logic on a physical host? As you said they might have logic to delay the payload by hours or days or even weeks on purpose
Short answer: you cannot. Whatever the programmer has written, that's what the malware is doing. That's how programming works, whatever you write, the system does. After the software is compiled, only specialised tools (which are not available for the general public) can to an extent, alter the behaviour by managing the CPU. You as a user cannot.
 
Short answer: you cannot. Whatever the programmer has written, that's what the malware is doing. That's how programming works, whatever you write, the system does. After the software is compiled, only specialised tools (which are not available for the general public) can to an extent, alter the behaviour by managing the CPU. You as a user cannot.
You're very knowledgeable. Are you a programmer, or a cybersecurity IT guy?
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top