Need feedback on Cybereason Ransomfree tool

goodlad

New member
Member
VIP
Local time
1:36 AM
Messages
239
I have installed this tool today, it seemed decent & was voted on the PC Mag list as well. But I just wanted to know if any one's using it and any pro's or con's to deal with ?

I don't restart my lappy often, usually send into sleep mode, when I'm away from it..
 

My Computer My Computer

At a glance

windows 7 ultimate x32T6670,8GB DDR3
Computer type
Laptop
Computer Manufacturer/Model Number
DELL
OS
windows 7 ultimate x32
CPU
T6670,
Motherboard
INTEL CORE 2 DUO, 0TFXK9
Memory
8GB DDR3
Screen Resolution
1366*768
Hard Drives
512GB SSD
Mouse
Logitech M165 w/sidebuttons
Internet Speed
30-150 mb/s
Antivirus
Bitdefender
Browser
FF, Opera GX

My Computers My Computers

  • At a glance

    Windows 11 Pro x64 [Latest Release and Releas...Ryzen 9 5950X, 3.8 - 5.2 MHz64GB [2 x 32GB] DDR4 3200MHz4GB NVIDIA GEFORCE GTX 1650 Ti
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • At a glance

    Windows 11 Pro x64 Latest RPIntel I7 10750H 5.0GHz32GB [2x16GB] DDR4 2933 MHznVidia GTX1650Ti 4 GB GDDR6
    Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
Several YouTube videos show it works well
 

My Computer My Computer

At a glance

win 8 32 bit
Computer type
PC/Desktop
OS
win 8 32 bit
Thanks for the feedback Barman58 & samuria :) I do take backups but not as often as recommended. Need to buy few more flash drives for more backups probably, I don't trust online backups at all. I knew someone who lost his entire online backup, after his mail account was hacked.

So far, the only discomfort I'm facing is.. watching obnoxious files & directories created by this software - yeah, they did mention about it as being honeypot prior to installation. Usually I delete most of the files & directories which I don't use.
 

My Computer My Computer

At a glance

windows 7 ultimate x32T6670,8GB DDR3
Computer type
Laptop
Computer Manufacturer/Model Number
DELL
OS
windows 7 ultimate x32
CPU
T6670,
Motherboard
INTEL CORE 2 DUO, 0TFXK9
Memory
8GB DDR3
Screen Resolution
1366*768
Hard Drives
512GB SSD
Mouse
Logitech M165 w/sidebuttons
Internet Speed
30-150 mb/s
Antivirus
Bitdefender
Browser
FF, Opera GX
Not used it myself but this review may help you decide - it's one possible addition to a proper backup regimen

RansomFree Is the Latest App That Tries to Stop Ransomware Infections on Windows

The article says pretty much the same things the program advertises on its website, it really doesn't adds much more than advertisement. Moreover it makes many claims and assumptions without any technical explanation or reference to back it up.
Let's see the exact problems:

RansomFree works by creating randomly-named folders throughout the filesystem that act as honeypots.

These folder names start with characters like ~ or ! because they are low on the ASCII table and thus will be scanned first by ransomware.

The assumption here is that files are encrypted by malware in ASCII (alphabetical) order and the software relies on changes on those honeypots to detect malware. There is NO justification at all on why malware would attack files in that particular order, or even if some does, there is no reason to think that every malware does the same. Besides, creating honeypots won't detract malware to attacking legitimate files afterwards. All this technique seems to rely on strong assumptions that aren't guaranteed at all and it doesn't explains why.
If I were writing a ransomware, it won't certainly sort files at all, but just encrypt in whatever order they come from the OS, maybe prioritizing some presumably sensitive names. And even if I were lured by a honeypot, it won't stop there for sure.


RansomFree monitors these files, and whenever they change, it detects the originating process and pauses it.

This assumes that the "antiransomware" has permissions to suspend the offending process. Even though Windows promotes the bad practice of running everything under an administrator account and is a frequent security flaw found in home computers, it might not be the case. Moreover, nothing prevents "something else" to simply resume the attacker. A virus running as two processes or as a higher privilege level will easily bypass this "protection".


In a limited set of tests carried out by Bleeping Computer, RansomFree stopped the latest version of Locky (Osiris), Cerber, and Globe.

What tests? What actually has been tested? How was the test setup and the target computer? What versions of the malware? How can anyone reproduce such tests?
This is a claim with zero evidence to back it up. Coincidentally, all those "antivirus tests" incur in the very same flaw.


CyberReason says that RansomFree can detect when an abnormal encryption-heavy process starts (specific to ransomware families), on both the local computer and on shared and/or network drives.

How does to detect it? Knowing what other processes are really doing is not exactly easy and very subject to false positives. Many programs legitimately do encryption, browsers, compression programs, anything that protected with a password, not to mention software like VeraCrypt whose sole purpose is to encrypt things. I would like to know how the detection takes place.

The downside is that RansomFree needs a short amount of time to detect the start of the encryption operations. This means that a few of your files will be encrypted before RansomFree detects anything wrong.

That means that it cannot stop it in time. Since it relies on honeypot files and the fact that they "should" be attacked first it doesn't do anything if legitimate files are chosen first. A ransomware encrypting files in inverse alphabetical order simply destroys all files before being detected. It can't even ensure what files are attacked before detection, and they may be some critical files (from the user point of view). Even antiviruses claim that they stop viruses before doing any harm!


Despite this, many users would happily sacrifice a few files if they can save the rest. However, the best course of staying safe from ransomware is to complement RansomFree with a solid computer backup policy.

Another unfounded claim. Sure losing a few is better to lose all, but RansomFree cannot ensure that only "few" files are lost and neither it can control what files. Importance of data is entirely defined by each user.
On a good note, here they do a good suggestion, to have a solid backup handy. This is actually the only piece of good advice I can find in the whole article.

What I read about it are strong claims with little to justify it, and many flaws with the technique are easy to identify. The article also completely fails in suggesting an alternative approach. For example, it completely ignores the protection given by permissions, by firewalls, by system and software updates, and only superficially mentions backups.
And most important, the sad fact that once a computer becomes infected, there is no way to make it clean other than a clean install and restore from a sane backup. This instead suggest trying to tame a running malware, an technique already proved to fail.
The software neither offers its source code for a security analysis, you must blindly trust it or discard it completely. A license is also missing, apparently.

Bottom line, I would not trust it. There is no indication of it doing anything but rudimentary analysis and lack of description of its techniques doesn't improves it. Of course, it may as well do some useful things, but we have no way of knowing it for sure.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64Intel Core i7-740QM8 GB DDR3NVIDIA GeForce 330GT
Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
The review is at bleeping computer, the defacto standard for malware prevention and cleaning, which is why I posted it.

Also if you read the full set of comments, that are always an essential part of any review on a specialist website ;), they cover, and actually agree with some, of your points.

If you wish to gain knowledge of the tests that BC use then if you ask a question on their forum I'm sure someone will give you full information, (obviously except for any proprietary or sensitive information) :)
 

My Computers My Computers

  • At a glance

    Windows 11 Pro x64 [Latest Release and Releas...Ryzen 9 5950X, 3.8 - 5.2 MHz64GB [2 x 32GB] DDR4 3200MHz4GB NVIDIA GEFORCE GTX 1650 Ti
    Computer type
    PC/Desktop
    Computer Manufacturer/Model Number
    ChillBlast - Custom to my design
    OS
    Windows 11 Pro x64 [Latest Release and Release Preview]
    CPU
    Ryzen 9 5950X, 3.8 - 5.2 MHz
    Motherboard
    Asus Prime X570-Pro
    Memory
    64GB [2 x 32GB] DDR4 3200MHz
    Graphics Card(s)
    4GB NVIDIA GEFORCE GTX 1650 Ti
    Sound Card
    On-board SPDIF to 5.1 System + HDMI [5.1 system]
    Monitor(s) Displays
    32" UHD 32 Bit HDR Monitor + 43" UHD 4K 32Bit HDR TV
    Screen Resolution
    2 x 3840 x 2160 @60Hz
    Hard Drives
    1TB M2 SSD OS, 500GB Fast Access SSD, 2 x 8TB Data + Various Externals from 1TB to 4TB, 10TB NAS
    PSU
    NZXT C750 80 PLUS Gold 750W Modular PSU
    Case
    Workstation Case [Matt Black]
    Cooling
    NZXT Kraken X63 280mm CPU Cooler +2x Quiet Case fans
    Keyboard
    Logitech Wireless MX Keys & K400 + others
    Mouse
    Logitech Wireless MX Master 3S
    Internet Speed
    920 MB Down 50 MB Up
    Antivirus
    BitDefender Total Security Pro
    Browser
    Chrome (always run latest Non-Beta)
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    Samsung 10.2" tablet
    Blackview TAB 8 4G Android Tablet c/w Keyboard
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control
  • At a glance

    Windows 11 Pro x64 Latest RPIntel I7 10750H 5.0GHz32GB [2x16GB] DDR4 2933 MHznVidia GTX1650Ti 4 GB GDDR6
    Computer type
    Laptop
    System Manufacturer/Model Number
    Dell XPS 17 10750H
    OS
    Windows 11 Pro x64 Latest RP
    CPU
    Intel I7 10750H 5.0GHz
    Motherboard
    Dell XPS
    Memory
    32GB [2x16GB] DDR4 2933 MHz
    Graphics Card(s)
    nVidia GTX1650Ti 4 GB GDDR6
    Sound Card
    Stock [Realtek] 4 Speaker
    Monitor(s) Displays
    17" IPS UHD+ Infinity Edge Touchscreen
    Screen Resolution
    3840 x 2400
    Hard Drives
    2TB M2 NVMe, 4TB External + various 500GB & 1TB External NVMe (also have access to spinner HDD from
    PSU
    Stock
    Case
    Stock XPS Aluminium & Carbon Fibre
    Cooling
    Stock - Active Fan Control
    Keyboard
    Backlit + Various Logitech
    Mouse
    Stock Track Pad + Logitech MX Trackball
    Internet Speed
    72 MB Down 18MB Up
    Browser
    Chrome
    Other Info
    Also run ...
    Laptop - Quad 8GB - Windows 10 Pro x64
    Nexus 7 Android tablet x2
    10.2" tablet
    Sony Z3 Android Smartphone
    Wacom Intuos Pro Medium Pen Pad
    Wacom Intuos Pro Small Pen Pad
    Wacom Expresskeys Remote
    Loopdeck+ Graphics Controller
    Shuttle Pro v2 Control Pad
    10TB NAS
The article was not intended to give all the exact testing that was done or could be done.
From where I'm sitting the article was intended for the average user to give some basic information.

To a large degree I understand Alejandro85 points, but I don't think the article was intended to address those points. The average user would get lost in all the high tech information. I know I would for sure.

Any anti virus, anti malware, or all the other various anti infection programs are very complicated under the hood and take proper training to understand.
It's also my understanding that much of the 'anti' programs have proprietary or sensitive information that the companies will not release. Obviously for good reasons.

Bleeping Computer was the first forum I joined many years ago. I don't go there often anymore. As far as I know they are still one of the Gold Standard of security forums.

Sign up at Bleeping Computer and give them a good looking over and ask questions.

Just my opinion

Jack
 

My Computer My Computer

At a glance

Windows 10 Pro. 64/ version 1709 Windows 7 Pr...Intel i7-6800K @ 4.3Corsair Platinum 16 gig @2400EVGA GTX 1070 OC
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I heard BitDefender is protecting from Ransomware as well for both Free & Premium users through their regular security updates. I have BD free version, now BD is performing quarantine on the files generated by Cybereason tool, found 6 files with in an week. It just says quarantined not an virus though when checked the details. So far, I don't have any performance issues. The only thing I don't like BD Free version is - they don't offer Manual Scan instantly unlike for Premium, other than that. Its the best I have used in a while, consumes very minimal resources, you won't even notice ifs scanning the system unlike Avira & Avast.
 

My Computer My Computer

At a glance

windows 7 ultimate x32T6670,8GB DDR3
Computer type
Laptop
Computer Manufacturer/Model Number
DELL
OS
windows 7 ultimate x32
CPU
T6670,
Motherboard
INTEL CORE 2 DUO, 0TFXK9
Memory
8GB DDR3
Screen Resolution
1366*768
Hard Drives
512GB SSD
Mouse
Logitech M165 w/sidebuttons
Internet Speed
30-150 mb/s
Antivirus
Bitdefender
Browser
FF, Opera GX
Back
Top