angryip / ipscan

Angry IP Scanner - fast and friendly network scanner
angryip.org
GNU General Public License v2.0
4.08k stars 715 forks source link

ipscan.exe 3.9.1 is labelled as malicious in CrowdStrike #441

Open BenAgin1 opened 5 months ago

BenAgin1 commented 5 months ago

Seemingly only this version of the app is getting labelled as malicious in CrowdStrike Falcon, while 3.8.2 is clean. I am curious as to what might have caused this update to be flagged as malicious.

https://www.virustotal.com/gui/file/ae50c71517182c9773bb138745f10a643b1215078ede439b2b3adb486a9cfb14

BrianBtheITguy commented 2 months ago

We are having this problem. I've had my security team add an exemption for this URL and it's still being removed during download https://objects.githubusercontent.com/github-production-release-asset-2e65be/1968850/125626c6-b346-4a46-9c68-fd2d426f8e48?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=releaseassetproduction%2F20240703%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20240703T210734Z&X-Amz-Expires=300&X-Amz-Signature=20f6597a7e7656e8669fd0a12f22585975109a8110bd340c8548cdb468b3064d&X-Amz-SignedHeaders=host&actor_id=0&key_id=0&repo_id=1968850&response-content-disposition=attachment%3B%20filename%3Dipscan-3.9.1-setup.exe&response-content-type=application%2Foctet-stream

eaglexeye69 commented 1 month ago

We use Crowdstrike too and it is being flagged and removed too.

Shapy06 commented 3 weeks ago

I have version 3.7.6 and my IT security team urgently asked me to uninstall everything because Cybereason had detected it as a highly dangerous program! (they have recently activated new security options). I would like to know what it is, I have been trusting this software for years...

JonnyTech commented 3 weeks ago

https://angryip.org/faq/virus.html