Skip to content

Virus detected in redu-0.2.12-windows-x86_64.zip by a small number of scanners #96

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
tomwaldnz opened this issue Apr 19, 2025 · 10 comments

Comments

@tomwaldnz
Copy link

I want to give redu a try, but when I downloaded it Windows Defender reported a virus - Trojan:Script/Wacatac.C!ml. Kaspersky online scan says the file is fine, . However, the VirusTotal scan says Kaspersky detected a virus but 66 other vendors didn't.

It's probably a false positive, but I thought it worth mentioning to be looked into.

Windows Defender
Windows Defender

Virus Total
Virus Total

In comparison v0.2.11 scans fine

Virus Total Scan 0.2.11
Virus Total Scan 0.2.11

@drdo
Copy link
Owner

drdo commented Apr 19, 2025

Hello,

Thank you for reporting this.

I'm not entirely sure what to do about it here, that binary was built by the Github action that is on this repo.
There is the possibility of some foul play from either Github Actions or one of redu's dependencies I suppose.

But I would be more inclined to bet on broken anti-virus software.

@tomwaldnz
Copy link
Author

I agree it's likely a false positive, but by reporting it you can look into it :)

@clifton-nav
Copy link

clifton-nav commented Apr 22, 2025

Image

CrowdStrike is labeling it as possibly malicious, too. I can't use it at work because of this and it does make a person hesitate to use it. Maybe you can figure out what is triggering it and fix it.

@drdo
Copy link
Owner

drdo commented Apr 22, 2025

Could you check if it's still happening for 0.2.13? Just wondering because I updated some dependencies as well for this version.

I checked with VirusTotal and Kaspersky online for 0.2.13 and both report it clean.

@clifton-nav
Copy link

Yes, I had just installed that version this morning, but I can ask for details. This came from my security officer in an email.

@clifton-nav
Copy link

Interestingly, I don't see a version on it. Is there a way to see it from the CLI?

Image

@clifton-nav
Copy link

I can send you a little more info in a private message. Where would I do that?

@drdo
Copy link
Owner

drdo commented Apr 22, 2025

Interestingly, I don't see a version on it. Is there a way to see it from the CLI?

Image

redu --version

@drdo
Copy link
Owner

drdo commented Apr 22, 2025

I can send you a little more info in a private message. Where would I do that?

I'm on Libera with nick drdo if that's convenient for you.

@tomwaldnz
Copy link
Author

Windows Defender still finds the same trojan in 0.2.13. Based on the two scanners below saying it's fine I suspect it's a false positive. I submitted the earlier version to Microsoft to analyze, hopefully they will fix it at some point.

Virus Total says it's clean

Image

Kaspersky says it's clean too.

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants