Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trojan detected by Windows Defender (Script/Wacatac.B!ml) #399

Open
Vasdranna opened this issue Dec 16, 2024 · 5 comments
Open

Trojan detected by Windows Defender (Script/Wacatac.B!ml) #399

Vasdranna opened this issue Dec 16, 2024 · 5 comments

Comments

@Vasdranna
Copy link

Vasdranna commented Dec 16, 2024

Hi, I just downloaded the Git repo and Windows defender triggered a virus alert.

I'm sure it's a false positive, I haven't found other similar posted issues but just in case I'm opening this one so I can have some information on the matter.

It was also triggered by 2/65 vendors in Virus Total:
https://www.virustotal.com/gui/file/e1bc78c9618944bd7accd5d2997a262c5a06f16cc8eae95a79498b02cb04224a

I'm on Windows 11, did anyone else experienced the same?

@oleg-shilo
Copy link
Owner

oleg-shilo commented Dec 17, 2024

Sadly I am also experiencing the same with WinDefender.
Since I am the author of the product I do trust the zip file content :)

WinDefender completely spits the dummy. When I scan the zip file that I have just created it's happy. When I upload it to github and download it immediately, it complains. If I extract the downloaded content and scan all files it's happy again.

It's extremely frustrating. I cannot publish it on winget as it only uses WinDefender. Chocolatey does VirusTotal and passes through the packages that have less than four positives.

I am trying to break this cycle by including extra text file in the zip so the byte signature is changed.

Can you please see if this zip file scans OK after the download. even without extracting?
https://github.com/oleg-shilo/cs-script/releases/download/v4.8.23.0/cs-script.win.v4.8.23.0.winget.zip

For your own safety please go to the latest release page and try to download cs-script.win.v4.8.23.0.winget.zip

Virus Total: gives it 100% OK https://www.virustotal.com/gui/file/8407c192671531b3a7c74eb61c52d83bed7fbe5caff71b7a0c56c17a1bd5291dfile/8407c192671531b3a7c74eb61c52d83bed7fbe5caff71b7a0c56c17a1bd5291d

I just want to see that other users have it OK too before I publish again

@oleg-shilo
Copy link
Owner

BTW Virus total reports ZERO for teh zip files downloaded from this repo release page.
So the file that you scanned and triggered 2/63 is not from this repo.

@oleg-shilo
Copy link
Owner

From now on I decided to publish the AV scanning results for all releases:

image

@Vasdranna
Copy link
Author

Vasdranna commented Dec 17, 2024

Sadly I am also experiencing the same with WinDefender. Since I am the author of the product I do trust the zip file content :)

WinDefender completely spits the dummy. When I scan the zip file that I have just created it's happy. When I upload it to github and download it immediately, it complains. If I extract the downloaded content and scan all files it's happy again.

It's extremely frustrating. I cannot publish it on winget as it only uses WinDefender. Chocolatey does VirusTotal and passes through the packages that have less than four positives.

I am trying to break this cycle by including extra text file in the zip so the byte signature is changed.

Can you please see if this zip file scans OK after the download. even without extracting? https://github.com/oleg-shilo/cs-script/releases/download/v4.8.23.0/cs-script.win.v4.8.23.0.winget.zip

For your own safety please go to the latest release page and try to download cs-script.win.v4.8.23.0.winget.zip

Virus Total: gives it 100% OK https://www.virustotal.com/gui/file/8407c192671531b3a7c74eb61c52d83bed7fbe5caff71b7a0c56c17a1bd5291dfile/8407c192671531b3a7c74eb61c52d83bed7fbe5caff71b7a0c56c17a1bd5291d

I just want to see that other users have it OK too before I publish again

Thank you for replying and for adding the reports to the release page, it does help.

Downloading from the releases is fine, but Virus Total still triggers 2/65 for the downloaded zip of the repo. Microsoft Defender stopped complaining at first, in fact, it passed the scan well now, but after sometime it triggered Trojan:Script/Wacatac.B!ml.

https://www.virustotal.com/gui/file/3746e08d04cf425efc32aeaabe0a2dd6fc713ca1cd4dde72b99a12b9d02f49c0

This is for the file that you get when you download the repo (Code > Download ZIP).

Thank you for your time, and for the tool! It's super useful, I think it should be a built-in feature of .NET.

@oleg-shilo
Copy link
Owner

oleg-shilo commented Dec 18, 2024

I removed a few zip files with the code samples with the hope that it would help with the master download. It looks like it did. This is how I scanned directly from the repo:
image
The good outcome of it is that on the release page here is now a link to the VirusTotal page that can scan the downloadable URLs from the release page directly. And the user can always have the current state by simply clicking the reanalyze button.


It is extremely frustrating when. Right now I cannot publish teh product on winget simply because a silly super aggressive AV flagged the file. While it is an Open-Source project, can you imagine something like this with the consumer product?

Or... in my prev company medical instruments manufacturing CrowdStrike decided to be cute and deleted old C++ compiler and stopped the production line for one day. When the CrowdStrike disaster happened I was so-o-o not surprised. Their attitude is shocking. These guys have no accountability. They can just randomly declare any product a suspect and effectively stop it from being used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants