Jump to content

User13

Members
  • Posts

    12
  • Joined

  • Last visited

Posts posted by User13

  1. Hi

    when I visit this link https://www.virustotal.com/gui/file/4364a60cc5f7039a24528452680648850d7b3f434c25892d1b3b5e5aa14898fb/detection/f-4364a60cc5f7039a24528452680648850d7b3f434c25892d1b3b5e5aa14898fb-1688041704

    it’s infected with PowerShell/TrojanDownloader I’m not sure if its real or false but in my settings, I choose for every automatic action to ask the end user (real time, web access, manual scan, etc.…) for web access scan usually there two option to disconnect or ignore and this should happen in this case because its downloading malware.

    But what really happened is that the malware downloaded and real time protection catches this malware and ask to clean or ignore and it pass the web protection.

    I tested this link in edge, chrome, firefox.

    In edge and chrome the same issue, but in firefox the malware downloaded with no alert at all but when you scan firefox cash folder you can find it there.

    Why the web access it's not strict in this case and pass the malware?

     

    Thanks

  2. It’s been detected by real time protection not web protection.

    For example:

    Go to https://www.eicar.org/download-anti-malware-testfile/

    Try downloading the zip EICAR when vpn active, the archive should be scanned by web protection but not the real time, the download completed without notification.

    (Clear your browsing cash) repeat the above but the vpn off a notification should be appear.

    This also happened for infected JS after they downloaded the real time detected them.

     

    In the other point https://rank.egybest.club/tv

    Alert of (Potentially unwanted content found) should ask the user if you want to ignore or go back, but not with vpn active.

×
×
  • Create New...