Closed fukusuket closed 2 weeks ago
It may be a temporary problem, so we will see how it goes for a while.
I tried again today and was able to download the file with no problems, so the issue is closed.
It is now reproducing again... :( I'll keep an eye on it for a while longer.
Sorry to bother you on this but Windows Defender blocking the download Hayabusa-2.16.0-win-x64.zip or hayabusa-2.16.0-all-platforms.zip to my Windows 10 box
Since Win Defender is triggering on a different file in the win-x64 .zip file than in the all-platforms zip file, I wanted to verify that the below files should be tagged as trojan in the related .zip files before I take them out of quarantine. I didnt see anything about these files specifically in the documentation
win-x64.zip file:
Trojan:Win32/Casdet!rfn hayabusa\hayabusa-2.HWXrULIn.16.0-win-x64.zip.part
all-platforms.zip file:
Trojan:PowerShell/Fleisnam.F \hayabusa-2.16.0-all-platforms\rules\sigma\builtin\process_creation\proc_creation_win_powershell_amsi_init_failed_bypass.yml
Trojan:PowerShell/Malgent!MSR \hayabusa\hayabusa-2.16.0-all-platforms\rules\sigma\sysmon\process_creation \proc_creation_win_powershell_amsi_init_failed_bypass.yml
Thank you
@yapper899 Thanks for letting us know. We will remove these rules from the next package until we implement encrypting of the rules in order to get around Windows Defender blocking things.
@fukusuket @yapper899 I updated the rules that do not include the rules that cause false positives here: https://github.com/Yamato-Security/hayabusa/releases/tag/v2.16.1 Please check to see if you can download it without errors.
@YamatoSecurity I have verified that I can download all the zips and run the exe! :) Thank you so much!
I have confirmed that hayabusa-2.17.0-win-x64.zip can be downloaded in Widows 11 :)
@fukusuket Thanks for checking! I think this was fixed after ignoring the problem rules with 2.16.1. I will close this issue for now but please re-open if you get alerts again.
Describe the bug It's not actually Hayabusa's bug ... :( but the browser(Edge/Chrome) is blocking the download, so the hayabusa-2.16.0-win-x64.zip binary is currently not downloadable on Windows 11.
Step to Reproduce
Expected behavior hayabusa-2.16.0-win-x64.zip is downloadable.
Actual behavior hayabusa-2.16.0-win-x64.zip is not downloadable as follows.
Screenshots
Environment (please complete the following information):
Additional context