arriven / db1000n

MIT License
1.18k stars 208 forks source link

Trojan #546

Open KostDark opened 2 years ago

KostDark commented 2 years ago

Hi,

The Windows defender catched Trojan:Win32/Trickbot!ml and Trojan:Win32/Sabsik.FL.A!ml in the 0.9.5 and 0.9.6 db1000n_windows_amd64.zip

roman-kruglov commented 2 years ago

Confirm, the same in my case. You can tell Win Defender to ignore it and still run the app as a temporary workaround.

arriven commented 2 years ago

Wait, but 0.9.4 and prior are not flagged? That's really weird as there aren't many changes between those

arriven commented 2 years ago

it could be that someone reported the executable and it got flagged. I've got reports that eset doesn't even allow you to download the archive and flags it as WinGo/DdosAgent.B (which seems to be defined purely for this app). It's weird that it is flagged as some random trojan by windows defender but it could be that they share some similar behavior (maybe we were hitting targets whose IPs were used by these trojans).

I also know that devs of UACyberShield had the same problem but most antiviruses stopped flagging them after couple of days (except ru ones ofc) so let's wait at least some time. In the meanwhile you can use docker or ignore the file in your antivirus