Not detected

Ransomware not detected, from fake mail attachment

Fake doc = downloader
https://www.virustotal.com/nb/file/bbb49a102c48ef3eeacb1d5a309f679b9abaade3659ccf863fb4a529b0339f91/analysis/1457039778/

Downloader payload = ransomware
https://www.virustotal.com/nb/file/d7a54e392cc051e8fae6d26431351d405fe9836e9467bde07187a8586e0e4fbb/analysis/1457039793/

It is on the way to avast lab :wink:

Theres an automated ransomware protection comong soon hopefully and finally…

I sincerely hope the HIPS update is ready too, oh wait, NO new BETA today?

The ransoware payload is now detected
https://virusscan.jotti.org/en-US/filescanjob/2bkmmf34gf

but not the downloader fake doc
https://virusscan.jotti.org/en-US/filescanjob/2k7hu469z2

I have two different samples sent
This should also be detected as JS:Locky-D [Trj]