TeraTermProject / teraterm

Other
389 stars 31 forks source link

Trojan detected from multiple AV Vendors in Version 5.0 and onward #206

Closed Elmeche closed 1 month ago

Elmeche commented 2 months ago

Dear TeraTermProject Team,

I've run the EXE binaries from the release section against VirusTotal and noticed, that in version 5.0 2 Antivirus Vendors and in version 5.1 & 5.2 3 Antivirus Vendors flag the executable as malicious, while the version 4.107 & 4.108 are benign from all AV vendors. It looks like the AI model of those Vendors apparently are detecting patterns of Trojans and Viruses. This might be most likely false positives from their AI models. But this will still prevent multiple system admins (and Users) from using version 5.0 (including my company).

My recommendation would be to contact these AV vendors and report the files as false positive. Also best would be if you include the check with VirusTotal and the later reporting of false positives in your release cycle,

zmatsuo commented 1 month ago

Report sent. Let's wait and see.

graham30rad commented 1 month ago

Virus total is still showing 3 hits..

zmatsuo commented 1 month ago

When I enter 5.2 exe URL ( https://github.com/TeraTermProject/teraterm/releases/download/v5.2/teraterm-5.2.exe ) on https://www.virustotal.com/gui/home/url , all clean.

zmatsuo commented 1 month ago

I had received E-mail from VirusTotal.

Here's part of the E-mail.

We understand your concern about new files being flagged as potentially harmful. While VirusTotal aggregates data from various antivirus engines, we don't make our own judgments about files.

It seems that there is nothing TeraTerm Project Team can do about false positive.