It’s better provide us file or SHA1 of file.

Please do report any malware you think is bypassing our Antivirus product please. (You won’t see this kind of request from our Competitors :wink: )…(and you know why! :))

Experienced members may want to test the possible bypasses themselves. They can request a download link to the malware from the poster by pm as usual and discuss it here.

There is very very few samples can by-pass default deny protection.
The only ■■■■■ on our shield is “Trusted-Whitelisted Malwares
Maybe the India team should check Trusted Vendor List for such examples. “Trusting a vendor completely” is wrong.

this topic is for actual “bypass”. Which means a malware that is able to jump out of our Sandbox/Containment due to some vulnerability or bug etc.
Human error (which is what you refer to when you mention whitelisting a malware) is not the subject of this thread. But thank you anyway.

So do you know any malware that can jump out of sandbox/containment as per above?


The question is not the ones we are able to sandbox and sent to us for analysis. Is there any that jumps out.

We would like to get your replies if you know any malware that is able to bypass Comodo Sandbox and the containtment; so that CCAV. If yes, please share with us.

We care about your security and protection, we have developed a hardened sandboxed environment and provide you the Default Deny Platform . With each and every new technique , we continue further improvements.

All your competitors ask for this, you are not the first one. One difference is that they usually pay for this kind of information.

May I ask how would we know if the file was malware? The way I see it (please correct me if I’m wrong) but if CCAV was unaware of a file (which could be legit) it would automatically get sandboxed. If a file was malware and was somehow allowed to run (say, trusted by user) CCAV wouldn’t alert us unless cloud detection (antivirus) said otherwise. In this scenario, it is likely the infected file would be going about it’s business without the user even knowing.

I think it would be useful to show a flow diagram how files (trusted/untrusted) are processed within CCAV and CIS showing the strengths and weaknesses of each.


Here is the Malware detection problem:

This section of forum must be in English, and your issue is not a by-pass of CCAV. It is just lack of signature to detect that malware.
Bypassing: Jumping out of our Containment
Detection: detecting malware or not.

two different things…