Jump to content

Recommended Posts

Posted (edited)

I obtained a malicious script on my pc for the purpose of placing it into online sandboxes for analysis when I accidentally ran it. A error popped up saying, “This file can’t run, contact your administrator”. But kaspersky didnt block anything. I tried running another safe script file and I got the same error, so it might have not ran - the hips logs says no script related processes have started. Whenever I tried placing this into online sandboxes, Safe Browsing gave me a malicious detection cause of the file, but when I tried scanning it, it came out clean. Am I infected?

Edited by Xeno2ig
Posted

I also have a HIPS setup where whenever trust cannnot be defined, it’s placed in “Untrusted” and I do not automatically trust digitally signed objects.

Posted

Welcome to Kaspersky Community,

 

I guess You have set up Your K. with Default Deny approach, in so, I would say You are not infected.

 

image.thumb.png.44b8107bc8de3edb6ea6e5c146d947d0.png

 

Anyway, In Reports -> Intrusion Prevention, You should check if there is some entry about a possible execution blocking.

Posted
3 hours ago, harlan4096 said:

Welcome to Kaspersky Community,

 

I guess You have set up Your K. with Default Deny approach, in so, I would say You are not infected.

 

image.thumb.png.44b8107bc8de3edb6ea6e5c146d947d0.png

 

Anyway, In Reports -> Intrusion Prevention, You should check if there is some entry about a possible execution blocking.

Nothing about any scripts executing

Posted

Probably that script could not run in Your system due to different cause, it needs some 3ar party apps and/or dlls, etc...

 

But that execution error may be also due to K. Default Deny approach...

Posted
1 hour ago, harlan4096 said:

Probably that script could not run in Your system due to different cause, it needs some 3ar party apps and/or dlls, etc...

 

But that execution error may be also due to K. Default Deny approach...

I also use Simple Windows Hardening - I’ve noticed any file scripts can’t run. I made one not malicious and I ran it, same error but not blocked by Kaspersky.

Anyways, does K Default Deny block JS Files?

Posted

Ah if using SWH then probably was the cause... some of the changes applied to the system.

 

Quote

Anyways, does K Default Deny block JS Files?

 

Yes, unless They are known and trusted by KSN, all the unknown in general -> Untrusted group -> Won't run.

  • Like 1
Posted
2 hours ago, harlan4096 said:

Ah if using SWH then probably was the cause... some of the changes applied to the system.

 

 

Yes, unless They are known and trusted by KSN, all the unknown in general -> Untrusted group -> Won't run.

Not sure what SWH does with scripts, but for me it seems they can’t run. I don’t mind that - I don’t use them.

Posted

Is there any reason though that whenever I scanned the file with right click it wasn’t detected, but whenever I uploaded it to an analysis website, Safe Browsing gave me a malicious script detected cause I was uploading it. 

Posted

Yes, there are some script files that have only sense when are immersed in site code, that's why K. sometimes only adds detections to Safe Browsing (Web AV) Module.

Posted

It’s a file on my computer, not just one for web scripts.

Posted

I did, it has a HEUR detection. Doesn’t detect it with HEUR via static scan though.

Posted

What is the purpose of that script?

Posted
2 часа назад, harlan4096 сказал:

What is the purpose of that script?

Not sure - detected as Trojan-PSW.

VT says it’s some sort of stealer.

Posted

Can You send me it via personal msg of the Community, compressed with password "infected".

Posted
2 часа назад, harlan4096 сказал:

Can You send me it via personal msg of the Community, compressed with password "infected".

I will when I get home.

I need to check if I had default deny enabled - I had to turn it off for something. No scripts are placed in low restricted (the default). Would I still be good?

Posted

If the script did not run... 🤷‍♂️

Posted
6 minutes ago, harlan4096 said:

If the script did not run... 🤷‍♂️

I’m ensuring it didn’t run - I’ve seen malware popup with fake errors - but it probably didn’t run cause of nothing weird in HIPS logs and SWH.

Posted

Send me, and I'll try it in one of my VMs.

Posted
14 minutes ago, harlan4096 said:

Send me, and I'll try it in one of my VMs.

I will in about a hour- that’s when I get home.

Posted

Buddy in the settings first check the reports and go to intrusion prevention, there you will get a range of information about a possible blockade. My bet in this case is that everything is caused by your use of SWH.

Posted

Finally, I tested that sample in VM without any type of hardening, and I also got that execution error, so that script seems not programmed to be executed, but used in Web environment...

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...