-
Notifications
You must be signed in to change notification settings - Fork 123
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Virus at esptool-0.4.9-win32.zip? #44
Comments
Releases are built on Appveyor, that's an automated build in a container. Then it is directly uploaded to GitHub. Honestly, I have no idea where to start looking for a potential source of infection... |
Most probably it is then false positive. I sent that file to F-Secure. Hopefully they will can give more information why it is detected as troijan. |
I got answer from F-Secure. They say that it is false positive and they will make update to db soon. |
Cisco and its Advanced Malware Protection (AMP) product is also detecting it as malware... Unfortunately, you need a contract with Cisco to report it as a false positive. |
I work for Cisco and I'll try to report it into that team. I did an in-depth analysis with Cisco ThreatGrid and there are two reasons it is triggering as malware: The second item is the larger issue in terms of why it is seen as malware. I don't know that you have any control over either of those issues via build options, but that's why it's triggering. |
Suddenly F-Secure remove esptool.exe
I download https://github.com/igrr/esptool-ck/releases/download/0.4.9/esptool-0.4.9-win32.zip and unzip it and it remove also that.
I upload exptool.exe to virustotal and result looks quite alarming https://www.virustotal.com/en/file/3b6691658dc47298f784a89321866e5519498fdc015aea27f9ad237667e799ab/analysis/1476526377/
8 / 46 virus scanners detect is as troijan. Is is compiled with infected machine?
The text was updated successfully, but these errors were encountered: