App Review Windows Defender vs Ransomware

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
NB InfoTech

struppigel

Moderator
Verified
Staff Member
Well-known
Apr 9, 2020
656
Ransomware-specific protection will, among others, check the following behaviour:
  • writing to AV specific bait files
  • modification of many files in a row
  • entropy increase in modified files
  • file extension change
  • shadow copy deletion
If one ransomware already encrypted files and bait files, other ransomware that would target the same files has nothing to do anymore (given that it searches by extensions which have already been changed).
It will not encrypt, not change entropy, not modify the bait files and therefore not show any malicious behaviour that might have been detected.

More general protection mechanisms also include the way samples were obtained, e.g., files that were downloaded via a browser have a specific identifier. These identifiers are missing here. Files that arrive via email attachments, downloaders, droppers or exploits, show certain malware typical patterns that are detected as well. None of these protection mechanisms have a chance in this artificial testing scenario.

Unless you actually want to protect your system from a scenario where you will execute hundrets of ransomware samples in a row, this test is not meaningful in any way.
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,158
The video as an anti-ransomware protection test has many flaws noted already in this thread. Anyway, it is a good basic presentation of the AV capabilities for educational purposes. it can also show that the protection of Defender free on default settings with additionally enabled Controlled Folder Access can be compromised by some sophisticated ransomware.
It seems that at least one sample (MedusaLocker) partially defeated Defender. Although the files in protected folders were not encrypted, some other files were successfully encrypted and the ransomware made the system unbootable for some reason (not uncovered in the video). For more comprehensive protection the Defender settings require enabling ASR rules. The MedusaLocker samples were used in the targeted attacks especially in the healthcare industry.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top