📜 ⬆️ ⬇️

Does your antivirus catch password-protected archives?

The other day a characteristic letter arrived to me:



Without looking, he flipped through, because it is clear that there is an accountant with the invoices. And this morning I cleaned the box, I had a minute, and I was curious what kind of “invoices” it was (looking ahead - the coder was in the letter).

The result is quite good - 31 of 56 :
')


And, apparently, a few free minutes were hit in the head, I decided to play around. I packed the file into the archive with a password and threw it on VT again. And, lo and behold! Already 2 out of 56 :



It seemed very remarkable who exactly remained on the list. Little-known Russian and French antivirus. Draw conclusions?

By the way, while writing the post, there were still crawls of detections on the unparted file, at the time of sending the post already 38.

Source: https://habr.com/ru/post/276347/


All Articles