Recent Results in March 2025

Latest DATA FROM the advanced in-the-wild malware test

Summary of March 2025

11

tested
solutions

567

unique
SAMPLES

501

malware hosted over HTTP

12

malware hosted over HTTPS

11

average malicious changes [1]

PRE-LAUNCH level prevention

0 %

POST-LAUNCH level protection

0 %

average blocked malware [2]

0 %

Potential data breaches

18
11 s

Average Industry
Remediation Time

* based on data telemetry

1.149 s

The quickest average remediation time

[1] The number of harmful changes made to Windows during dynamic analysis of the malware sample.
[2] Average blocking of malware by all tested solutions, regardless of level of prevention or protection.

Unique Occurrence Threat Categories

200

backdoor C&C

3

keylogger

37

credentials stealer

4

kali linux meterpreter

16

ransomware

13

trojan downloader

6

banking trojan

13

remote access trojan

TOP 3

HIJACKED SERVERS LOCATION

0
0
0

TOP 3

TLD COMPROMISED DOMAINS​

.com

0

.net

0

.ru

0

Examples illustrating the blocking of malware in the test

LOLBins in statistical terms

Legitimate and trusted software and built-in components in Windows are often used by cybercriminals to hide malicious activity. The so-called “Living off the Land Binaries” (LOLBin) are necessary for the proper functioning of the operating system. During a cyberattack, it can be difficult or impossible to block them, making them a very attractive method for malware developers. Below we present the most commonly used LOLBin in this edition of the test.

rundll32.exe
3138
certutil.exe
2031
schtasks.exe
1999
consent.exe
1000
tor.exe
585
powershell.exe
288

Malware Comparison Table in March 2025

The following summary shows a comparison of tested solutions to protect workstations against malware. We encourage you to become familiar with a detailed description and read our testing methodology in order to understand the results.

PRE-LAUNCH: The classification concerns detecting malware samples before they are launched in the system.
POST-LAUNCH: The analysis level, i.e. a virus has been run and blocked by a tested product.
FAIL: The failure, i.e. a virus hasn’t been blocked and it has infected a system.
Sandbox Column: Number of indicators, i.e. malicious changes made to the system without the anti-virus installed.

Automatic Average Remediation Time (RT): The time expressed in seconds counted from the introduction of malware into the system by the browser, through the launch to the detecting and resolving a security incident.

Certificates are granted to solutions that are characterized by a high level of security, with a rating of at least 99% of blocked threats in the Advanced In-The-Wild Malware Test.

Our tests comply with the guidelines of the Anti-Malware Testing Standards Organization.
Details about the test are available at this website as well as in our methodology.

Recent Results in March 2025

enterprise products

Emsisoft Enterprise Security + EDR
excellent
PRE-LAUNCH:
28.01%
POST-LAUNCH:
71.99%

Blocked: 607/607
Total: 100%
RT: 0.105 second

mks_vir Endpoint Security
excellent
PRE-LAUNCH:
81.55%
POST-LAUNCH:
14.45%

Blocked: 607/607
Total: 100%
RT: 2.9 seconds

ThreatDown Endpoint Protection + EDR
excellent
PRE-LAUNCH:
58.65%
POST-LAUNCH:
41.35%

Blocked: 607/607
Total: 100%
RT: 100 seconds

Xcitium ZeroThreat Advanced + EDR
excellent
PRE-LAUNCH:
41.68%
POST-LAUNCH:
58.32%

Blocked: 607/607
Total: 100%
RT: 10.1 seconds

home products

Avast Free Antivirus
excellent
PRE-LAUNCH:
55.52%
POST-LAUNCH:
44.48%

Blocked: 607/607
Total: 100%
RT: 13.8 seconds

Bitdefender Total Protection
excellent
PRE-LAUNCH:
96.38%
POST-LAUNCH:
3.62%

Blocked: 607/607
Total: 100%
RT: 3.1 seconds

Comodo-logo.svg
Comodo Internet Security 2025
excellent
PRE-LAUNCH:
28.17%
POST-LAUNCH:
71.83%

Blocked: 607/607
Total: 100%
RT: 5.1 seconds

F-Secure Total
excellent
PRE-LAUNCH:
66.72%
POST-LAUNCH:
33.28%

Blocked: 607/607
Total: 100%
RT: 8 seconds

K7 Total Security
excellent
PRE-LAUNCH:
44.65%
POST-LAUNCH:
55.35%

Blocked: 607/607
Total: 100%
RT: 5.1 seconds

Malwarebytes Premium
excellent
PRE-LAUNCH:
56.01%
POST-LAUNCH:
43.99%

Blocked: 607/607
Total: 100%
RT: 110 seconds

Microsoft Defender
excellent
PRE-LAUNCH:
6.92%
POST-LAUNCH:
93.08%

Blocked: 607/607
Total: 100%
RT: 49.1 seconds

Norton Antivirus Plus
excellent
PRE-LAUNCH:
52.39%
POST-LAUNCH:
47.61%

Blocked: 607/607
Total: 100%
RT: 1.4 seconds

Panda-Security-logo
Panda Dome Advanced
excellent
PRE-LAUNCH:
84.84%
POST-LAUNCH:
14.33%
FAIL:
0.82%

Blocked: 602/607
Total: 99.18%
RT: 37.8 seconds
FAIL: 5

Quick Heal Total Security
excellent
PRE-LAUNCH:
71.99%
POST-LAUNCH:
28.01%

Blocked: 607/607
Total: 100%
RT: 36 seconds

Webroot Antivirus
excellent
PRE-LAUNCH:
50.74%
POST-LAUNCH:
49.26%

Blocked: 607/607
Total: 100%
RT: 126 seconds

ZoneAlarm Extreme Security NextGen
excellent
PRE-LAUNCH:
55.02%
POST-LAUNCH:
44.48%
FAIL:
0.49%

Blocked: 604/607
Total: 99.87%
RT: 47 seconds
FAIL: 3

Related Publication in Details

Dive into our latest publication, dedicated to security test against malware. Uncover analyses, methodology, and results that provide invaluable insights into the latest edition of the Advanced In-The-Wild Malware Test.