@Sempf Isn’t this exactly why the EICAR string was created?
Conversation
Notices
-
Embed this notice
Jake Hildreth (acorn) :blacker_heart_outline: (horse@infosec.exchange)'s status on Tuesday, 23-Apr-2024 18:52:09 JST Jake Hildreth (acorn) :blacker_heart_outline: -
Embed this notice
VessOnSecurity (bontchev@infosec.exchange)'s status on Tuesday, 23-Apr-2024 20:47:27 JST VessOnSecurity @horse @Sempf No. Besides, anyone detecting that string under such circumstances is doing it wrong. The string must be detection only if residing in the first 68 bytes of a file that is no larger than 128 bytes.
Among other things, this attack shows why detecting malware based on scan strings alone is a bad idea. What is this, year 1988? Honestly, I expected better from Kaspersky.
-
Embed this notice