angryip / ipscan

Angry IP Scanner - fast and friendly network scanner
angryip.org
GNU General Public License v2.0
4.16k stars 717 forks source link

Trojan.Diple.amki #394

Open ghost opened 1 year ago

ghost commented 1 year ago

Hi, I've just wanted to download new version of AngryIP, but when I checked it on virustotal.com, he found "1 security vendor and no sandboxes flagged this file as malicious", such as Trojan.Diple.amki. I checked it on microsoft official website, where it says:

"Trojan:Win32/Diple.A is a trojan that allows unauthorized remote access and control of an affected computer. The trojan attempts to connect to a remote server using a specific port to accept and execute commands from a remote attacker. The trojan could download an arbitrary file and run it as "%TEMP%\csrssd.exe"."

(https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan:Win32/Diple.A)

absalan commented 1 year ago

Any updates on this? I got same result.

ghost commented 1 year ago

Still the same.

angryziber commented 1 year ago

All the builds of ipscan on github releases are built by Github actions from the source code available here. You can check that there are no trojans in the source code.

Security vendors have a history of falsely flagging Angry IP Scanner just in case. This is their business to flag stuff, the more they flag, the better the business goes. Please help by letting them know of false positives. Build the Angry IP Scanner yourself from the source if in doubt.

ghost commented 1 year ago

Okey then and Tnx. I used same AngryIP scanner before, and when was time to do an update, I checked it just in case and VirusTotal showed probably false positive. Not the first time, but thank you again for your response. You helped a lot :)