Author Topic: YourRansom ransomware  (Read 2620 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
YourRansom ransomware
« on: February 10, 2017, 10:14:38 AM »
download sample
hxxps://files.fm/down.php?i=7dcqrj5z&n=YourRansom.7z

password zip : infected
i create password because i want to protect avast member here , please try at vmware/virtualbox

it blocked by FileRep-malware

but just want test behavior protection , only disable file system shield , others default setting

result : failed to protected
« Last Edit: February 10, 2017, 10:44:59 AM by ymchen »

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: YourRansom ransomware
« Reply #1 on: February 10, 2017, 10:21:16 AM »
Hi,

It is blocked by filerepmalware.Maybe someone from avast team as to why IDP didn't block it?

I will try contacting someone from avast team on this.

Offline HonzaZ

  • Avast team
  • Advanced Poster
  • *
  • Posts: 1038
Re: YourRansom ransomware
« Reply #2 on: February 10, 2017, 11:07:20 AM »
IDP (behavior shield) is by no means supposed to be the only shield running; it is a complement to file system shield and web shield. While there are some samples that are detected by only one (or two) of the most important shields, I do not consider it a fail :)
But we of course work very hard to improve individual shields ;)!

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: YourRansom ransomware
« Reply #3 on: February 10, 2017, 11:09:05 AM »
IDP (behavior shield) is by no means supposed to be the only shield running; it is a complement to file system shield and web shield. While there are some samples that are detected by only one (or two) of the most important shields, I do not consider it a fail :)
But we of course work very hard to improve individual shields ;)!

As I expected! Thanks for shedding some light.

REDACTED

  • Guest
Re: YourRansom ransomware
« Reply #4 on: February 10, 2017, 11:37:01 AM »
IDP (behavior shield) is by no means supposed to be the only shield running; it is a complement to file system shield and web shield. While there are some samples that are detected by only one (or two) of the most important shields, I do not consider it a fail :)
But we of course work very hard to improve individual shields ;)!

really appreaciate and thx for the work hard  ;D

REDACTED

  • Guest
Re: YourRansom ransomware
« Reply #5 on: February 10, 2017, 09:37:17 PM »
Hi,

It is blocked by filerepmalware.Maybe someone from avast team as to why IDP didn't block it?

I will try contacting someone from avast team on this.

try this one , now avast miss detect
https://www.upload.ee/files/6659867/2017.2.11-03.Ransom.YourRansom.7z.html
password : infected

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: YourRansom ransomware
« Reply #6 on: February 11, 2017, 04:18:20 AM »
Hi,

It is blocked by filerepmalware.Maybe someone from avast team as to why IDP didn't block it?

I will try contacting someone from avast team on this.

try this one , now avast miss detect
https://www.upload.ee/files/6659867/2017.2.11-03.Ransom.YourRansom.7z.html
password : infected
Avast hardened mode aggressive will protect you from that but Avast CC and BB/BS failed to recognize this new ransomware.So no matter what you are protected. ;)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline TrueIndian

  • Poster
  • *
  • Posts: 433
Re: YourRansom ransomware
« Reply #7 on: February 11, 2017, 04:49:02 AM »
Its blocked too  :)

Avast labs are very quick to react to new ransom samples  ;)

Just because VT doesn't say we detect doesn't mean avast doesn't block the url or the binary:
https://www.virustotal.com/en/file/b6eb979579aa43fdfad147a4821b4a12c2745be994e4de563a61d23e219fd72f/analysis/1486785235/

This may have been flagged first by filerep then by their labs as malware-gen
« Last Edit: February 11, 2017, 04:55:13 AM by TI199 »