Wednesday, April 20, 2016

Symantec Misses on Dropper

A malicious Microsoft Word File w/associated macro is making its way across the Internet this morning.  How do we know?  Our Forcepoint Sandbox detected it... report here.

Unfortunately, and as is the case all too often, Symantec is not detecting this malware as proven by VirusTotal:


What makes us so certain that this file is indeed malicious?  Per below, it's pulling another file down via HTTP:


What does that prove you may ask?  Per below, that file is detected as another Dropper by our Forcepoint ACE Engine which is resident on our proxies:


In summary, AntiVirus is a commodity.  Do not buy into the pitch that it will solve your security problems.  Reduce your security spend on AV and insert Next Gen Security Solutions.  Call ESPO Systems for a free consultation/demonstration.