NEZNAMY / TAB

"That" TAB plugin.
Apache License 2.0
904 stars 246 forks source link

Trojan trace in TAB last version Trojan:Script/Wacatac.B!ml #1371

Closed CtrlAiDel closed 1 month ago

CtrlAiDel commented 1 month ago

Server version

pufferfish 1.21

TAB version

4.1.9

Stack trace

Chrome and edge are deleting the file 4.1.6 was fine

Steps to reproduce (if known)

No response

Additional info

Trojan:Script/Wacatac.B!ml

Checklist

NEZNAMY commented 1 month ago

https://www.spigotmc.org/threads/windows-defender-false-positives.639507/

CtrlAiDel commented 1 month ago

Thank you

HauserGrim commented 1 month ago

I compiled the plugin from sources (v4 branch) and it has no problems with windows defender: tab-my.zip https://www.virustotal.com/gui/file/c3b3971a1ccce7abec93cb95bddfcbabecfbc621cdcdd8c27f0bd2d07ed493ff Same as 4.1.8 from releases: https://www.virustotal.com/gui/file/baacd0989e0f1182ddfb9ef6f3563e710a05ff61475cbcbf3162970ebdb9438b Unlike 4.1.9 from releases: https://www.virustotal.com/gui/file/be3e0459e675fcf93ca7fcacc2044c1711c434c44ffd7a68cd359d924ad18c86

NEZNAMY commented 1 month ago

https://github.com/NEZNAMY/TAB/wiki/Frequently-Asked-Questions#18---why-is-the-plugin-flagged-as-a-virus-by-windows-defender

It does for me using jar I compile myself. What if you try master branch? I'm getting the same result there too.

HauserGrim commented 1 month ago

4.1.8, compiled 4.1.9, compiled master do not cause this, only 4.1.9 from releases. I even decompiled 4.1.9 from the releases and the one I compiled, but decompilied code is the same. Perhaps there is some minimal difference when building on different systems or jdk. Either way, I don't think there's any point in wasting time on this.

NEZNAMY commented 1 month ago

Correct, there is no point in wasting time on this.