maciejkaczkowski / rhl

recALL Hash Library
9 stars 3 forks source link

Recently being flagged as Malware? False positive? #1

Open itsdrinkingthewater opened 6 years ago

itsdrinkingthewater commented 6 years ago

win32\Delf (Pasword Stealer): https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=PWS:Win32/Delf

And other heuristics claiming Trojan\back door: https://www.virustotal.com/#/file/b4549662aa0167573b16a24b677986385cbc9c325b44b73a0a0aa41038cbae73/detection

maciejkaczkowski commented 6 years ago

It's false positive. The problem you are reporting is related to the recALL program, not the RHL library.

You can try preview release: http://download.keit.co/preview/

less popular, less false reports https://www.virustotal.com/#/url/6c84e303a6e632b3d201db2e5fa215721deafa338e1301d938e42e9080a75817/detection

itsdrinkingthewater commented 6 years ago

Thanks dude. you're a stand up dude if you're actually not weaponizing this tool (without us knowing)