Bryce792 / ApotheoticAdditions

Apotheosis Addon
5 stars 3 forks source link

apotheotic_additions1.5.jar trojan:script/wacatac.B!ml #23

Closed GrizzBear01 closed 3 months ago

GrizzBear01 commented 3 months ago

file is flagged as trojan and removed as soon as its downloaded

downloaded from curseforge

Screenshot 2024-03-05 190909

Gbergz commented 3 months ago

can confirm this, detected by bitdefender while scanning it. bild

Bryce792 commented 3 months ago

Going to attempt to replicate this, was this via curseforge launcher, or manual download?

Gbergz commented 3 months ago

CurseForge Launcher is where I grabbed and scanned the jar. Edit: But just downloading the jar from CF sites yields the same results when scanning.

Edit 2: Here's Virustotals site results: https://www.virustotal.com/gui/file/bf58450deee9e32d01f90b88d53906063709272ebacb5d7297b92249e60f5754

Bryce792 commented 3 months ago

So after doing some research, and un-compiling the mod, it looks like its mainly the mcCreator code that is flagging it as a false positive. After removing the JAR file and placing it in a seperate folder outside of the jar and scanning that, it came up as fine, but for some reason scanning the jar flags it as a trojan. Untitled

I'm going to look more into this, and most likely attempt to rebuild the mod off of mcCreator if that is the case.

Gbergz commented 3 months ago

Gotcha, so it's a false positive. A relief for users reporting this then.

Bryce792 commented 3 months ago

Looking at the VirusTotal link provided, nearly every single one of the details is from the mcCreator code. I ran a scan of the actual mcCreator workspace aswell, which appears clean too. details workspace

Bryce792 commented 3 months ago

Discovered files creating the false positive, they were unadded structure files, they have since been removed from the latest version of the mod, and versions 1.4 - 1.4.5.1 are now archived due this issue being present in all of them.

Gbergz commented 3 months ago

You Archived v1.4 - v1.4.5.1, but v1.5 is also having that issue, as initially reported.

Bryce792 commented 3 months ago

Missed that part tbh, just archived 1.5 aswell. Thank you for the heads up.