Closed Gigafloppagus closed 8 months ago
Regarding this topic, please see what I already indicated here: https://github.com/dpradov/keynote-nf/issues/635
As it is quite annoying and certainly means that there are people who cannot use the application at work, where very restrictive policies are usually applied on the use of "unknown" applications, I have obtained a certificate for code signing, with which I will sign the following versions. It should help prevent some engines from flagging them as suspicious, and also help Microsoft's Smart Screen warn you about installing an app from an unknown editor.
Sorry to ask, but why does keynote-nf delete and write the driver Windows\system32\spool\DRIVERS\x64\3\mxdwdui.BUD?
Well, I would have to investigate it, I don't know. I assume it will be related to the component used for printing (Note | Print Note...) (File | Page setup ) All the code used, both the one created by me and the one corresponding to 3rd party components, is available on GitHub, if you want to take a look. In particular: https://github.com/dpradov/keynote-nf/tree/master/3rd_party/richprint
Regards Daniel
By the way, as a curiosity, look at the total virus analysis of the same file, but passing the URL to the location on GitHub: https://www.virustotal.com/gui/url/3ebd197d6d22775bf1cb09b97a691d7e4b3492d2688da3ac9f02388515ec69b4?nocache=1
Daniel,
Thank you so much for your quick and thorough response. Reading #635 was helpful.
A certificate for code signing will hopefully remove some of these headaches! Not being flagged, especially by some of the AI-based tools included at virustotal, can seem like not just a moving target but a target with moving goal posts, as well. Some of the behavior across file uploads and URL scanning is indeed curious.
As for mxdwdui.BUD, I will take a look at https://github.com/dpradov/keynote-nf/tree/master/3rd_party/richprint.
Thanks again.
Last version, 1.9.0, is code signed and it is not flagged as malicious. (See #652)
Hello, and thank you for your hard work.
KeyNoteNF_1.8.5.1 is regrettably flagged by some security vendors.
The sandbox Zenbox flags this file as: MALWARE RANSOM TROJAN. It seems some of the reasons are
Masquerading behavior: Drops files with a non matching file extension (content does not match to file extension)
Virtualization/Sandbox Evasion: Contains medium sleeps (>= 30s) Contains long sleeps (>= 3 min) May sleep (evasive loops) to hinder dynamic analysis
Cf. https://www.virustotal.com/gui/file/a1c605d8fa66867158eab2deedad99d051864d466b96ea1b920cc46723e3dcf4/behavior
Sorry to ask, but why does keynote-nf delete and write the driver Windows\system32\spool\DRIVERS\x64\3\mxdwdui.BUD?
Apologies for bringing this up.