Neo23x0 / signature-base

YARA signature and IOC database for my scanners and tools
Other
2.49k stars 605 forks source link

False Positive Notice - Trojan Characteristics (WhatsApp) #291

Closed Esky580 closed 1 year ago

Esky580 commented 1 year ago

The following event with the title "Notive - Trojan characteristics":

Event Info
ApplicationId | App -- | -- Commandline | "C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2339.13.0_x64__cv1g1gvanyjgm\WhatsApp.exe" -ServerName:App.AppXkf4yh0averk473g9chjmra34tgccdh3d.mca Correlation_ActivityID|{00000000-0000-0000-0000-000000000000} Description_1| Trojan Characteristics DirectoryTableBase|0x2322B3000 EventID| 4 Execution_ProcessID|4294967295 Execution_ThreadID|4294967295 ExitStatus|259 Field|CommandLine Flags|9 ImageFileName|WhatsApp.exe Keywords|0x0 Level|0 Matched_1|\whatsapp.exe Module|ApplyIOCs Opcode|4 PackageFullName|5319275A.WhatsAppDesktop_2.2339.13.0_x64__cv1g1gvanyjgm ParentId|0x530 ProcessId|0x2EA0 Provider_Guid|{3D6FA8D0-FE05-11D0-9DDA-00C04FD7BA7C} Provider_Name|SystemTraceProvider-Process Score_1|65 SessionId|1 Sigtype_1|0 Task|0 TimeCreated_SystemTime|2023-10-10T23:06:02.5699318+02:00 UniqueProcessKey|0xFFFF8E81FDAF4080 VersioN|4 Winversion|22000 aurora_eventid|1301 level|notice msg|Filename IOC match found time|2023-10-10T23:06:04+02:00 _Match|\whatsapp.exe _Description|Trojan Characteristics _Author|Nextron

VirusTotal gives me the following Info:
"No security vendors and no sandboxes flagged this file as malicious"
url: https://www.virustotal.com/gui/file/e3d0b7506d8faf1f1a2fb986bb53b906b67ee95ba6401cdd4715bf54ce4d7a52/details
MD5| 5768fa1fa82010af49e6e95acea8c01f
SHA-1 |dd7d4aded71d46a5988777e193a7e42a0029412e
SHA-256 |e3d0b7506d8faf1f1a2fb986bb53b906b67ee95ba6401cdd4715bf54ce4d7a52
Vhash |0250451d15161"z
Authentihash |cded327cafd306f8343eff64f907612f1144b0c3116e1cbc8ef7b4bbefcb2de5
Imphash |f12299573f995fc0c70b04fabebb3e6c
SSDEEP |384:8N7ziSmUj6Q/0Baxc8IcbUi+7AOv6HMf82utc2NEwzXpQT34aOe9sRS872UVTSIM:8N7ziSmUjzfEIy34arSlay34abmn
TLSH |T13254EF31B37CC086EA41EE74CC20E7A547356E5B9920A81A70FEF32EB37A658DDE4541

phantinuss commented 1 year ago

will be fixed with PR https://github.com/Neo23x0/signature-base/pull/294

Thanks for reporting!