5 ms·
Pretty depressing. Only 2 out of 54 scanners currently detect something in the zips of the spyware. https://www.virustotal.com/en-gb/file/6ee40b8e7d49f4ea70b7c
by nysv 12y ago
Pretty depressing. Only 2 out of 54 scanners currently detect something in the zips of the spyware.
https://www.virustotal.com/en-gb/file/6ee40b8e7d49f4ea70b7ce5ca55a445897395323cd298a40baca76432a3a13bc/analysis/ https://www.virustotal.com/en-gb/file/6ee40b8e7d49f4ea70b7ce...
https://www.virustotal.com/en-gb/file/688f1e15390faf8d977351572a9a5c84d5bb228135ebd6c4c306708a9420f359/analysis/ https://www.virustotal.com/en-gb/file/688f1e15390faf8d977351...
- Zigurd 12y agoWAY too many security companies play both sides of the fence.
- Kalium 12y agoMore like anti-virus companies are just bad at what they do.
- Strom 12y agoThose zips are encrypted, that's why. I have included links to the unencrypted results [1,2], with ~80% detection rate. Notable green checkmark by Microsoft, perhaps FinFisher made extra sure to not get caught by Microsoft's heuristics? [1] https://www.virustotal.com/en-gb/file/f827c92fbe832db3f09f47fe0dcaafd89b40c7064ab90833a1f418f2d1e75e8e/analysis/ https://www.virustotal.com/en-gb/file/f827c92fbe832db3f09f47... [2] https://www.virustotal.com/en-gb/file/0b465877a998a993a64a146c80beaea2adf8e854644709706c6173a853ec8dba/analysis/ https://www.virustotal.com/en-gb/file/0b465877a998a993a64a14...
- nysv 12y agoMicrosoft too detects them now. Too late, but at least they are updating their signatures fairly rapidly. Interestingly, both files were first uploaded to VT in 2010, meaning that AV vendors have had chances to analyze them.
- rplnt 12y agoMalware vendors usually use these services to test their load. They wouldn't release anything that would get detected on day 0. And I think antivirus vendors do more in-house analysis only if there are reasons to - such as votes from users, or other AVs detecting the sample.