BlackArch / blackarch-site

BlackArch Linux website
https://www.blackarch.org/
122 stars 84 forks source link

Trojan activity #146

Closed Idlefase closed 3 years ago

Idlefase commented 3 years ago

Dear Blackarch,

Ive scanned your domain with virustotal and it stated by three av vendors that it was deemed malicious.

Then i scanned it with any.run and it stated that it was clean.

So i went ahead and visited the site.

I got blocked from entering the site by malwarebytes due to trojan activity.

My question here is, are you aware of this activity? Your site has been flagged for this for months.

I would love to hear your reaction.

All the best,

Idlefase aka vilematrix.

ikstream commented 3 years ago

Ive scanned your domain with virustotal and it stated by three av vendors that it was deemed malicious.

The first one with precrime, evaluated domain names and rates them if they are likely to relate to malicious stuff. \<sarcasm> this sounds like a really good idea to me \</sarcasm>.

The next vendor uses linked malicious domains as ranking. Thinks like gist.github.com are malicious to them...

The third one with the four letters is the only one, that looked valid to me, as they build their ranking also on hosted files/packages. Some of our linked packages might be deemed malicious by some AV softwares. Like parts of the seclist repo might trigger some AV.

I tried to check Malwarebytes as well, but after some limited searching I couldn't find any useful information. I wasn't in the mood to install their software on a VM and jump through the loops to open a false positive issue without knowing what it is actually based on.

The huge majority of tools ranks our site as clean as listed on virustotal. You are the first one to report a block, so it doesn't seem to be an issue for many people.

In the end we provide hacking tools, so I expect some software to get triggered.

If you can provide more info on why the Trojan alert was triggered please feel encouraged to do so.

Idlefase commented 3 years ago

Thanks for clearing things up.

Its good to know that it likely was a false positive.

I admit i could have guessed that it might be safe since any.run ( very large and advanced service). Stated it was clean.

Their attack matrix ( a part of it which uses a mind map to list all activity) stated that blackarch.org only peforms normal expected site behaviour. Like the use of a TLS cert and oscp. Etc

My excuses if i opend a issue way to soon.

Thank you in advance for taking it serious.

All the best

Idlefase

noraj commented 3 years ago

@Idlefase Don't hesitate to add a comment on VT using the #benign tag.

Idlefase commented 3 years ago

@noraj I will do that when i have the time for it.