jbilcke-hf / ai-comic-factory

Generate comic panels using a LLM + SDXL. Powered by Hugging Face 🤗
https://aicomicfactory.app
Apache License 2.0
973 stars 204 forks source link

Why does the virustotal tags this site as “malicious”? #2

Closed guhjy closed 11 months ago

guhjy commented 11 months ago

Why does the virustotal tags this site as “malicious”?

jbilcke-hf commented 11 months ago

Hi, do you have an example?

I've just done the test and I don't see any particular issue:

https://www.virustotal.com/gui/url/3f1e69046030e34cac70c192b02bf079918fd997a9169a06e64965691b908ffe?nocache=1

Capture d’écran 2023-09-25 à 18 16 44
guhjy commented 11 months ago

https://www.virustotal.com/gui/url/120182c8db1d14f126475ff2fbabd0d93205c4d80abab958b851afcf401ca31b

jbilcke-hf commented 11 months ago

Oh I see, this a problem with huggingface.co and not the codebase of https://github.com/jbilcke-hf/ai-comic-factory

https://www.virustotal.com/gui/url/453cb49f45b2d3e3003607d9987cfb5ca578753f989a8319ebc27ad4ecfad156

I don't develop or maintain huggingface.co, but it appears that you can just ignore this warning.

There are only two alarms out of 90, and you should check them manually:

Alarm 1 (CRDF): if you check manually by going to the CRDF website, it says:

Threats found on the website:
EICAR Test-NOT virus!!!
Eicar-Signature
EICAR Test File (NOT a Virus!)
EICAR-Test-File

Which is a false alarm (proof: https://en.wikipedia.org/wiki/EICAR_test_file )

huggingface.co contains a virus detector (this is to prevent people from uploading viruses), so it probably has some kind of database or list of virus signatures or test signatures in javascript

Alarm 2 (Quottera): same here, there is nothing to be worried about, if you check manually on Quottera it says there is nothing to be alarmed of, so the whole thing is a false alarm: https://quttera.com/detailed_report/huggingface.co