geofffranks / spruce

A BOSH template merge tool
MIT License
426 stars 77 forks source link

virustotal alert Trojan.WinGo.Rozena #370

Open c33s opened 1 year ago

c33s commented 1 year ago

i know go binaries can easily have false positives but explicit referral to Trojan.WinGo.Rozena is new for me.

i scanned the file spruce-windows-amd64 1.30.1

https://www.virustotal.com/gui/file/ac4993cb2830aebecb1957dcb263af152bbe92f6a7838a4ac57b1716e505e42f/detection

image

geofffranks commented 1 year ago

It's showing as clean for me:

https://www.virustotal.com/gui/url/5d5066d638a12bdbaab494251b5a2c6ae073845c3589f2921e0828b9b2ca4735/summary

is this still flagged for you?

c33s commented 1 year ago

as far as i see the url check of virustotal does not "fully" check the binary. if you download the file and upload it in the file tab of virustotal it leads to an in-depth check.