Open taskmann opened 1 year ago
@taskmann: It should be a false alarm.
It may trigger that since it contains a path to the hosts file in the PE executable strings. You should encode or split these system paths, as well as system registry paths.
The file was downloaded from here:
Maybe its false alarm, but if you have doubts, you can use docker and download the server configuration manually
Is this a false positive?
https://www.virustotal.com/gui/file/042d95237bd729a254ef95a62920b4db28a4d3161c0dcfef46029e15286b38f3
Trojan.PSW.Mimikatz.bjm Trojan.Generic@AI.80 (RDML:NHK6LALpQ Trojan.Malware.300983.susgen