
Real-World Test of Selected Products
What are we testing?
Webroot - heavily reliant on cloud and behavioural analysis, the software uses hash-based protection and pre-execution heuristics (dynamic analysis). It also makes use of behavioural monitoring, journalling and rollback. The Webroot extension provides real time Phishing protection by inspecting page linguistics and overall structure for signs of phishing.
ZoneAlarm - product makes use of dynamic emulation, inspecting files with 60+ AI engines in real time. It offers standard antivirus, reputation-based antivirus, CDR and real-time phishing protection.
Eset - a well known package. Offers standard antivirus, behavioural monitoring, HIPS and anti-phishing protection. The most premium version includes cloud emulation.
Trend Micro - the software is heavily based on signatures and machine learning that's being ran only on files with low prevalence.
4 Products
Various threats
Tolerance: 1 fraudulent site
Section 1: known & unknown phishing links.
These links will test products abilities to block already known and pre-analysed phishing. In some cases, they may rely on real-time analysis. For example, ZoneAlarm and Webroot both use real-time inspection. Evidence suggests that Eset creates definitions/heuristics as part of the AV scanner, that can potentially detect unknown phishing pages.
Spoofed brand: | Link |
---|---|
Netflix | https://amitsharmaxx.github.io/Netflix-clone-/signup/sign_up.html |
https://mipallab.github.io/facebook/index.html | |
Booking.com Extranet | https://hotel-id368076.com/sign-in |
Mobile.de | https://haendlers-bewertung.de/daten.html |
AT&T | https://ghghhjjhfgfhj.weebly.com |
AT&T Web Mail | https://onteamatt-100120.weeblysite.com/ |
BT | https://bt-login-3982.webflow.io/ |
BT | https://orange116419.studio.site |
https://contact.bmsupportcenter.com/appeal_case_id |