Neo23x0 / signature-base

YARA signature and IOC database for my scanners and tools
Other
2.44k stars 599 forks source link

False positive Trojan:Script/Phonzy.A!ml #319

Open groupecraft opened 4 months ago

groupecraft commented 4 months ago

detected by windows defender as Trojan:Script/Phonzy.A!ml as zip format

here are the files concerned signatures/sigma-rules/public/windows/powershell/powershell_classic/posh_pc_tamper_windows_defender_set_mp.yml signatures/sigma-rules/public/windows/powershell/powershell_script/posh_ps_tamper_windows_defender_set_mp.yml webfile: B:\dl\aurora-agent-lite-win-pack.zip|https://update1.nextron-systems.com/getupdate.php?product=aurora-agent-lite-win&|pid:6480,ProcessStart:133584569049788482