Author Topic: CyberCapture  (Read 133506 times)

0 Members and 1 Guest are viewing this topic.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #60 on: June 26, 2016, 02:34:06 AM »
Bypass, evasion, not being detected, same thing, end result is user being infected. At the end of the day, I frankly don't care how you call it.

I'd need Be Secure to confirm whether it triggered CyberCapture and the verdict was "CLEAN" or it didn't even trigger it...
It didn't even trigger CyberCapture.
Quote
CyberCapture will evolve in next months and its limitations (the origin of the file) will be narrowed.
Hope so. :)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: CyberCapture
« Reply #61 on: June 26, 2016, 06:59:02 AM »
But how did you obtain the sample? Downloaded from web or executed locally after unpacking it from archive? I think that may be a problem because I don't think avast! tracks files this thoroughly to know what arrived from web and what is local. If EXE gets downloaded and is unknown it'll CyberCapture it. If it arrives in a locked archive, you unpack it manually later on and execute the content, CyberCapture won't do anything, despite archive originating from web, because it couldn't do anything with it at the time.

Also, does CyberCapture even work if user decides to only install File System Shield and no Web Shield? One would think CyberCapture depends on Web Shield. Not installing it renders CyberCapture useless even if you have it ticked in the settings. Or does it?
Visit my webpage Angry Sheep Blog

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #62 on: June 26, 2016, 07:18:42 AM »
how did you obtain the sample? Downloaded from web or executed locally after unpacking it from archive?
Yes.Downloaded from web then executed locally.I have another Virus link and i PMed you the link pls try it yourself on wondows 7,because windows10 does not support this.VT-https://www.virustotal.com/en/file/879fc214c53f27097fa0a975046ff3a2435f602c8f64f1030c412ad14a656105/analysis/This will open CC but failed to block it.Say It clean.Send it to Viruslab.
« Last Edit: June 26, 2016, 07:30:40 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #63 on: June 26, 2016, 07:25:08 AM »
does CyberCapture even work if user decides to only install File System Shield and no Web Shield? One would think CyberCapture depends on Web Shield. Not installing it renders CyberCapture useless even if you have it ticked in the settings. Or does it?
Don't Know.Avast! Dev will answar this. :)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2293
Re: CyberCapture
« Reply #64 on: June 27, 2016, 01:07:55 PM »
how did you obtain the sample? Downloaded from web or executed locally after unpacking it from archive?
Yes.Downloaded from web then executed locally.I have another Virus link and i PMed you the link pls try it yourself on wondows 7,because windows10 does not support this.VT-https://www.virustotal.com/en/file/879fc214c53f27097fa0a975046ff3a2435f602c8f64f1030c412ad14a656105/analysis/This will open CC but failed to block it.Say It clean.Send it to Viruslab.
Hello Be Secure,
what was the exact scenario you have tried? Can you describe step by step what did you do with the file, please?

Milos

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #65 on: June 27, 2016, 01:22:11 PM »
how did you obtain the sample? Downloaded from web or executed locally after unpacking it from archive?
Yes.Downloaded from web then executed locally.I have another Virus link and i PMed you the link pls try it yourself on wondows 7,because windows10 does not support this.VT-https://www.virustotal.com/en/file/879fc214c53f27097fa0a975046ff3a2435f602c8f64f1030c412ad14a656105/analysis/This will open CC but failed to block it.Say It clean.Send it to Viruslab.
Hello Be Secure,
what was the exact scenario you have tried? Can you describe step by step what did you do with the file, please?

Milos
1.Download a virus file from web.
              2.executed it locally(Net was connected)and then the DeepScreen(Only word was changed.As you can see in pic.It was not even state that it was CC)apeared.
               3.After scan it state that file is clean not infected but it was a infected exe file.
In short-Downloaded from web then executed locally and failed to protect.
« Last Edit: June 27, 2016, 01:36:44 PM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2293
Re: CyberCapture
« Reply #66 on: June 27, 2016, 02:53:07 PM »
Thanks for the info. We will investigate the issue.

Milos

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #67 on: June 27, 2016, 02:58:25 PM »
Thanks for the info. We will investigate the issue.

Milos
Pls let me know. :)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: CyberCapture
« Reply #68 on: June 28, 2016, 02:48:04 AM »
Thanks for jumping Milos.
The best things in life are free.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: CyberCapture
« Reply #69 on: June 28, 2016, 04:03:21 AM »
The team has analyzed this scenario and found some bugs in the CyberCapture backend that might've been responsible for this. Fixes are on the way. Thanks for bringing this up by the way -- and please, if you see more issues (any misses in detection etc.), make sure to share them with us. We're committed to making CyberCapture a kick-ass thing and y'all's help is essential in this.

Thanks!
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #70 on: June 28, 2016, 04:13:25 AM »
The team has analyzed this scenario and found some bugs in the CyberCapture backend that might've been responsible for this. Fixes are on the way. Thanks for bringing this up by the way -- and please, if you see more issues (any misses in detection etc.), make sure to share them with us. We're committed to making CyberCapture a kick-ass thing and y'all's help is essential in this.

Thanks!
Vlk
I will.But CyberCapture needs a separate Section in the forum to report any kind off BUGS and improvments news on CC.@Vlk
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #71 on: June 28, 2016, 08:09:32 AM »
Pls remove its limitations from(USB origin,VBS files,BAT)quickly.
« Last Edit: June 28, 2016, 09:11:18 AM by Be Secure »
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89012
  • No support PMs thanks
Re: CyberCapture
« Reply #72 on: June 28, 2016, 03:10:17 PM »
Pls remove its limitations from(USB origin,VBS files,BAT)quickly.

I suggest we do what was said - by Vlk I believe - lets get the CyberCapture web downloads function sorted and bug free before adding additional entry point functionality.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48541
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: CyberCapture
« Reply #73 on: June 28, 2016, 03:13:06 PM »
Pls remove its limitations from(USB origin,VBS files,BAT)quickly.

I suggest we do what was said - by Vlk I believe - lets get the CyberCapture web downloads function sorted and bug free before adding additional entry point functionality.
Considering that the internet is the source of the biggest danger, it needs to be tackled and concord first. Once that's done, then it's time to move on to the next largest
source of attack.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Be Secure

  • Long Time Avast User(10years.....) Security Enthusiast.
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1908
Re: CyberCapture
« Reply #74 on: June 28, 2016, 04:26:24 PM »
Pls remove its limitations from(USB origin,VBS files,BAT)quickly.

I suggest we do what was said - by Vlk I believe - lets get the CyberCapture web downloads function sorted and bug free before adding additional entry point functionality.
Considering that the internet is the source of the biggest danger, it needs to be tackled and concord first. Once that's done, then it's time to move on to the next largest
source of attack.
Yes.But VBS files,BAT files are net base threats and have to be analyzed by CC. :)
PC- Windows10 EDU 64Bit,avast! free 21.1.2449,uBlock Origin,NVT_OSA,GoogleChrome(64bit),CCleaner,Unchecky,ZAM Free,Shadow Defender.
Security Enthusiast