Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

poshdeob.py detected as malicious (VirusTotal) #32

Closed
foxalfabravo opened this issue Jan 4, 2022 · 2 comments
Closed

poshdeob.py detected as malicious (VirusTotal) #32

foxalfabravo opened this issue Jan 4, 2022 · 2 comments

Comments

@foxalfabravo
Copy link

On VT today,
Kaspersky: HEUR:Trojan.PowerShell.Generic
Bkav Pro: ASP.Webshell
https://www.virustotal.com/gui/file/c044aa7e5851f152a734265e00677bd667dca5cad37a80335c4433d92b74b17b

@dc3-tsd
Copy link
Member

dc3-tsd commented Jan 6, 2022

Thank you for letting us know about this. The Kaspersky finding is a false positive associated with examples within docstrings so we are going to see if there is a clean way to resolve this without making the internal documentation worse. Bkav Pro is a false positive based on a list of lookup terms that can't be changed.

@dc3-tsd
Copy link
Member

dc3-tsd commented Jan 10, 2022

The 3.5.0 release has resolved the finding from Kaspersky, but the false positive is still present from Bkav Pro. This issue is being closed as making a change to address the false positive would reduce MWCP's functionality.

@dc3-tsd dc3-tsd closed this as completed Jan 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants