Skip to content
  • Categories
  • KForum
  • KClub
  • KClub Discord
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Kaspersky Beta

  1. Home
  2. ENGLISH USER FORUM
  3. Home
  4. Kaspersky
  5. Archive
  6. 2021
  7. [2021] Application Control (HIPS, SW, Firewall, IDS, TAM)
  8. Can not detect and block some ransomware sample

Can not detect and block some ransomware sample

Scheduled Pinned Locked Moved [2021] Application Control (HIPS, SW, Firewall, IDS, TAM)
7 Posts 3 Posters 4.9k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • huang1111H Offline
    huang1111H Offline
    huang1111
    [2021] Diamond BT
    wrote on last edited by Jarvis
    #1

    <p><strong>Reproduction steps:</strong></p>
    <p><span><img src="https://cloud.qainfo.ru/s/zNCv7EJMqNggv1K" alt="" />This problem is more serious, there are questions about SW defense ransomware</span></p>
    <p>Virus sample download address 1 (normal version): <a href="https://cloud.qainfo.ru/s/SshTyjY2pPikmjZ" target="_blank" rel="noopener">https://cloud.qainfo.ru/s/SshTyjY2pPikmjZ</a></p>
    <p>Virus sample download address 2 (using VMP): <a href="https://cloud.qainfo.ru/s/M3mNmNTJ5aVZcvu" target="_blank" rel="noopener">https://cloud.qainfo.ru/s/M3mNmNTJ5aVZcvu</a></p>
    <p>Double-click the sample as shown in this image (https://cloud.qainfo.ru/s/zNCv7EJMqNggv1K)</p>
    <p><img src="https://cloud.qainfo.ru/s/zNCv7EJMqNggv1K" alt="https://cloud.qainfo.ru/s/zNCv7EJMqNggv1K" /></p>
    <p><strong>Actual result:</strong></p>
    <p><span>Defense failure</span></p>
    <p><strong>Expected Result:</strong></p>
    <p><span>Defense success</span></p>
    <p><span></span></p>
    <p><span>There are still some words that I want to say to the development team:This is no accident. When the ransomware modifies the original files without deleting them, Kaspersky’s defenses are ineffective. I have discovered this problem more than once. I thought I uploaded them to the anti-virus department. I will pay attention to it, but the result is very disappointing. They just learn my sample machine and not solve the problem of SW.</span></p>

    1 Reply Last reply
    0
    • JarvisJ Offline
      JarvisJ Offline
      Jarvis
      wrote on last edited by
      #2

      hello!
      If there are no files on desktop to encode - nothing happens, KIS don't detect anything
      If there are any file to encode - KIS detect and delete ransomware, when timer gets 0

      huang1111H 2 Replies Last reply
      0
      • JarvisJ Jarvis

        hello!
        If there are no files on desktop to encode - nothing happens, KIS don't detect anything
        If there are any file to encode - KIS detect and delete ransomware, when timer gets 0

        huang1111H Offline
        huang1111H Offline
        huang1111
        [2021] Diamond BT
        wrote on last edited by huang1111
        #3

        <p>@jarvis said in <a href="/post/5967" target="_blank" rel="noopener">Kaspersky System Watcher Defect</a>:</p>
        <blockquote>hello! If there are no files on desktop to encode - nothing happens, KIS don't detect anything If there are any file to encode - KIS detect and delete ransomware, when timer gets 0</blockquote>
        <p>Hello, the timer time is 30 seconds, I just tested it, Kaspersky still miss (at this time, Kaspersky virus database is already the latest version), jpg images stored on the desktop can not turn on.If you can't reproduce it, please try the Chinese version of Kaspersky.</p>

        1 Reply Last reply
        0
        • Wesly.ZhangW Offline
          Wesly.ZhangW Offline
          Wesly.Zhang
          Moderators
          wrote on last edited by
          #4

          <p>The sample is from <a href="https://bbs.kafan.cn/thread-2155970-1-1.html" target="_blank" rel="noopener">here</a> if I don't guess incorrectly. <img src="/plugins/nodebb-plugin-composer-kl/vendor/tinymce/plugins/emoticons/img/smiley-cool.gif" alt="cool" /> This sample is very intersting.</p>

          Go! The world ! 💪 Our CD8/CD4 T lymphocytes are on their way to destroy the new tubular virus.😠
          If I don't reply your post here, Please send a PM in KL Community forum or post a E-Mail ( wesly.zhang@qq.com ) to notice me.

          huang1111H 1 Reply Last reply
          0
          • Wesly.ZhangW Wesly.Zhang

            <p>The sample is from <a href="https://bbs.kafan.cn/thread-2155970-1-1.html" target="_blank" rel="noopener">here</a> if I don't guess incorrectly. <img src="/plugins/nodebb-plugin-composer-kl/vendor/tinymce/plugins/emoticons/img/smiley-cool.gif" alt="cool" /> This sample is very intersting.</p>

            huang1111H Offline
            huang1111H Offline
            huang1111
            [2021] Diamond BT
            wrote on last edited by
            #5

            <p><span><span>@ wesly-zhang在</span></span><a href="/post/5975" target="_blank" rel="noopener"><span><span>卡巴斯基系统观察者缺陷中说</span></span></a><span><span>:</span></span></p>
            <blockquote>
            <p><span><span>如果我没猜错</span><span>,样本就是从</span></span><a href="https://bbs.kafan.cn/thread-2155970-1-1.html" target="_blank" rel="noopener"><span><span>这里来的</span></span></a><span><span>。</span></span><img src="/plugins/nodebb-plugin-composer-kl/vendor/tinymce/plugins/emoticons/img/smiley-cool.gif" alt="凉" /><span><span>这个样本非常有趣。</span></span></p>
            </blockquote>
            <p>这个样本是温馨小屋那个会员测试以后PM我的,卡巴检测不出来,但我不清楚为啥他们这边可以检测出来<img src="/plugins/nodebb-plugin-composer-kl/vendor/tinymce/plugins/emoticons/img/smiley-cool.gif" alt="cool" />我已经在上传一段视频到G云盘,你方便看的话也看一下</p>

            1 Reply Last reply
            0
            • JarvisJ Jarvis

              hello!
              If there are no files on desktop to encode - nothing happens, KIS don't detect anything
              If there are any file to encode - KIS detect and delete ransomware, when timer gets 0

              huang1111H Offline
              huang1111H Offline
              huang1111
              [2021] Diamond BT
              wrote on last edited by
              #6

              <p>@jarvis said in <a href="/post/5967" target="_blank" rel="noopener">Kaspersky System Watcher Defect</a>:</p>
              <blockquote>hello! If there are no files on desktop to encode - nothing happens, KIS don't detect anything If there are any file to encode - KIS detect and delete ransomware, when timer gets 0</blockquote>
              <p>Hello, I recorded a video, please take a look: https://drive.google.com/file/d/1G7RS4q3AsX5derEhSPvFd5pyJlGGljVB/view?usp=sharing</p>

              1 Reply Last reply
              0
              • JarvisJ Offline
                JarvisJ Offline
                Jarvis
                wrote on last edited by
                #7

                Cannot Reproduce

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Don't have an account? Register

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • KForum
                • KClub
                • KClub Discord