Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

1.20.3 Windows executable trips multiple AV warnings #485

Open
lairdb opened this issue Mar 31, 2024 · 4 comments
Open

1.20.3 Windows executable trips multiple AV warnings #485

lairdb opened this issue Mar 31, 2024 · 4 comments

Comments

@lairdb
Copy link

lairdb commented Mar 31, 2024

The executable release of 1.20.3 trips Chrome's AV and Windows Defender, which reports "Trojan:Win32/Meterpreter!ml"

VirusTotal also indicates positive for the zip and for the exe, as does jotti.org.

Similar scanning of 1.20.2 zip does not show any positives, but 1.20.2 exe also triggers alerts at VirusTotal.

Edit: Jotti shows concerns with both the 1.20.2 zip and the exe.

@sorinsky
Copy link

sorinsky commented Apr 7, 2024

Likewise, constant warnings, varying over time.

@floriegl
Copy link
Contributor

floriegl commented May 7, 2024

I think it has something to do with the one file bundling of PyInstaller as this drops all the files into an %localAppData%/_MEIxxxxxx folder which looks suspicious to antivirus programs. Maybe changing this to a one folder distribution (having all the support files in e.g., /dist would help with that.

@Der-Henning
Copy link
Owner

In PR #494 I modified the workflow to use onefolder for windows releases.
I don't receive any AV warnings with the resulting build.
Could you please verify?
Result: https://github.com/Der-Henning/tgtg/actions/runs/9147252262/artifacts/1516997749

@floriegl
Copy link
Contributor

I scanned the two zip layers and the EXE and the EXE got the most hits. But we got down from about 40 hits to now 12 (could be more in the future as AVs sometimes start to detect files only a bit in the future). I don't think there is much that can be done against the AI detections and the other results also sound more or less reasonable e.g., Trojan/Python.Kryptik, Python:Scanner-I [Trj], Trojan-Spy.Python.TelegramBot
https://www.virustotal.com/gui/file/f716382cdd95ba14a2650d3e4ce6501c2e6160360b0189783bdf7e5222d6bed7/detection

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants