Recent Results in January 2024

Latest DATA FROM the advanced in-the-wild malware test

Threat Landscape in January 2024

10
tested
solutions
300
unique
SAMPLES
300
malware hosted over HTTP
50
malware hosted over HTTPS
30
average malicious changes [1]

PRE-LAUNCH level prevention

50 %

POST-LAUNCH level protection

40 %

average blocked malware [2]

90 %

Potential data breaches

0
50 s

Average Industry
Remediation Time

* based on data telemetry

0 s

The quickest average remediation time

[1] The number of harmful changes made to Windows during dynamic analysis of the malware sample.
[2] Average blocking of malware by all tested solutions, regardless of level of prevention or protection.

TOP 3

HIJACKED SERVERS LOCATION

140
50
50

TOP 3

TLD COMPROMISED DOMAINS​

.com

190

.net

20

.top

10

TOP 10

FASCINATING SIGNATURES

Trojan.Mardom
Trojan.MSILZilla
Trojan.Agent.GIAK
HEUR.VBA.Trojan
Trojan.Femato.2
Generic.Trojan.Stealer.D
DeepScan:Generic.Malware.GFW
HEUR.RoundKick.W
Generic.PrintSpoofer.1
Generic.AsyncRAT.Marte.B

* data based on the mks_vir engine

LOLBins in statistical terms

Legitimate and trusted software and built-in components in Windows are often used by cybercriminals to hide malicious activity. The so-called “Living off the Land Binaries” (LOLBin) are necessary for the proper functioning of the operating system. During a cyberattack, it can be difficult or impossible to block them, making them a very attractive method for malware developers. Below we present the most commonly used LOLBin in this edition of the test.

rundll32.exe
1354
powershell.exe
705
wmiprvse.exe
402
schtasks.exe
370
consent.exe
359
taskhost.exe
315
iexplore.exe
186

Malware Comparison Table in January 2024

The following summary shows a comparison of tested solutions to protect workstations against malware. We encourage you to become familiar with a detailed description and read our testing methodology in order to understand the results.

PRE-LAUNCH: The classification concerns detecting malware samples before they are launched in the system.
POST-LAUNCH: The analysis level, i.e. a virus has been run and blocked by a tested product.
FAIL: The failure, i.e. a virus hasn’t been blocked and it has infected a system.
Sandbox Column: Number of indicators, i.e. malicious changes made to the system without the anti-virus installed.

Automatic Average Remediation Time (RT): The time expressed in seconds from the introduction of malware into the system by a browser, through the launch to detecting and resolving security incident. Occurs only at the POST-Launch level.

Certificates are granted to solutions that are characterized by a high level of security, with a rating of at least 99% of blocked threats in the Advanced In-The-Wild Malware Test.

Our tests comply with the guidelines of the Anti-Malware Testing Standards Organization.
Details about the test are available at this website as well as in our methodology.

Recent Results in January 2024

Avast Free Antivirus
excellent
PRE-LAUNCH:
71.05%
POST-LAUNCH:
28.95%

Blocked: 380/380
Total: 100%
RT: 4 seconds

Cegis Cyber
excellent
PRE-LAUNCH:
91.58%
POST-LAUNCH:
8.16%
FAIL:
0.26%

Blocked: 379/380
Total: 99,74%
RT: 13 seconds
FAIL: 1

Comodo-logo.svg
Comodo Internet Security
excellent
PRE-LAUNCH:
39.47%
POST-LAUNCH:
60.53%

Blocked: 380/380
Total: 100%
RT: 92 seconds

Emsisoft Enterprise Security
excellent
PRE-LAUNCH:
52.89%
POST-LAUNCH:
47.11%

Blocked: 380/380
Total: 100%
RT: 67 seconds

F-Secure Total
excellent
PRE-LAUNCH:
71.32%
POST-LAUNCH:
28.24%
FAIL:
0.26%

Blocked: 379/380
Total: 99,74%
RT: 5 seconds
FAIL: 1

Malwarebytes Premium
excellent
PRE-LAUNCH:
69.21%
POST-LAUNCH:
30.79%

Blocked: 380/380
Total: 100%
RT: 41 seconds

mcafee logo
McAfee Total Protection
excellent
PRE-LAUNCH:
2.63%
POST-LAUNCH:
97.37%

Blocked: 380/380
Total: 100%
RT: 108 seconds

Microsoft Defender
excellent
PRE-LAUNCH:
2.11%
POST-LAUNCH:
97.37%
FAIL:
0.53%

Blocked: 378/380
Total: 99,47%
RT: 143 seconds
FAIL: 2

Panda-Security-logo
Panda Dome Advanced
excellent
PRE-LAUNCH:
85.53%
POST-LAUNCH:
13.95%
FAIL:
0.53%

Blocked: 378/380
Total: 99,47%
RT: 18 seconds
FAIL: 2

ThreatDown Endpoint Protection
excellent
PRE-LAUNCH:
69.47%
POST-LAUNCH:
30.53%

Blocked: 380/380
Total: 100%
RT: 34 seconds

Webroot Antivirus
excellent
PRE-LAUNCH:
52.11%
POST-LAUNCH:
47.63%
FAIL:
0.26%

Blocked: 379/380
Total: 99,74%
RT: 28 seconds
FAIL: 1

Xcitium ZeroThreat Advanced
excellent
PRE-LAUNCH:
41.58%
POST-LAUNCH:
58.42%

Blocked: 380/380
Total: 100%
RT: 54 seconds

Related Publication in Details

Dive into our latest publication, dedicated to security test against malware. Uncover analyses, methodology, and results that provide invaluable insights into the latest edition of the Advanced In-The-Wild Malware Test.

See the previous results

You can always go back in time and check how each individual security product performed during previous editions of the test. We make the results from all previous tests available to you to verify if your favorite developer has improved protection against latest malware in his security software.

Menu