Author Topic: MBR Destroyer Malware  (Read 1294 times)

0 Members and 1 Guest are viewing this topic.

Offline Mr. Consumer

  • Full Member
  • ***
  • Posts: 134
MBR Destroyer Malware
« on: December 24, 2022, 03:34:32 PM »
It's a MBR destroyer malware that was able to bypass some products like Avast, Bitdefender, ESET. Also bypassed Avast's CyberCapture, ESET's cloud sandbox and some public sandbox services gave it only a 6/10 malicious confidence.
So I guess it's not easy to detect it. I tested it on a VM with Avast and it wasn't bootable anymore after restart.
Anyway, I hope the Avast team can find some kind of heuristic detection for it to block similar variants and update the behavior blocker to block malware like this. For example, Avira, Norton, Kaspersky detected it by heuristics prior to execution.
I submitted to Avast already:

https://www.virustotal.com/gui/file/667de29aacfd4418c1e7612e2beeea40c271e7b7df4261bff0ecfea1e6df15cf/detection

Edit: To my surprise, within 10 minutes of my submission now it's detected as "FileRepMalware [Misc]" for the main one, and I also tried changing file hash which was detected as "Win64:Trojan-gen". So it's not just a file based hash blocking. It actually found something malicious in the code and created a signature and pushed via stream updates.
WoW! So an automated generic detection in less than 10 minutes? That's super impressive. Not sure if any other products have this kind of fast automated signature creation system. I was aware of Avast's automation but didn't know that it can even create generic detections like this.
I still hope an Avast analyst get a hold of sample like this one and also cover it via behavior detection if possible so that Avast can protect user whether the sample was previously seen by Avast or not. MBR can be destroyed in less than a second, so it's important to protect it.
« Last Edit: December 24, 2022, 04:20:39 PM by Mr. Consumer »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: MBR Destroyer Malware
« Reply #1 on: December 24, 2022, 06:48:36 PM »
At VT you will see the file is being flagged by 14 vendors and missed by sandboxes.

Interesting Comment
Quote
malwationaima

9 hours ago
Threat Zone Analysis:

Verdict: Suspicious
Report: -https://app.threat.zone/submission/6b52c2b4-19ab-4297-827c-0b76c2fdaa83

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!