Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Virustotal reporting malware in mosquitto-2.0.20-install-windows-x64 #3172

Open
IASN-CCC opened this issue Nov 26, 2024 · 2 comments
Open

Virustotal reporting malware in mosquitto-2.0.20-install-windows-x64 #3172

IASN-CCC opened this issue Nov 26, 2024 · 2 comments
Labels
Status: Available No one has claimed responsibility for resolving this issue.

Comments

@IASN-CCC
Copy link

Wanting to Install Mosquitto on Windows however VT is showing malware related results
image

I tried another scanning tool that also showed a similar result

I know its only 1/72 but we have a pretty strict policy on any detection of a file as our internal rules mean that the file is deleted on any VT result making it hard to install

thank you

@github-actions github-actions bot added the Status: Available No one has claimed responsibility for resolving this issue. label Nov 26, 2024
@ralight
Copy link
Contributor

ralight commented Nov 27, 2024

I'm not sure what to say - the package is built on github CI, I'd hope that isn't compromised. More tellingly, searching for "bkav pro w32.aidetectmalware" shows many instances of false positives caused by this check.

@ItzLevvie
Copy link

ItzLevvie commented Dec 23, 2024

@IASN-CCC Your company should adjust those internal rules since the scores from VirusTotal are somewhat meaningless and should never be relied on.

0 flags does not always mean that there is no malware; and 7 or more flags does not always mean that there is malware.

It should follow the rules stated as per https://docs.virustotal.com/docs/false-positive-contacts

As for Bkav Pro - it is just a false positive caused by AI/ML and you should contact them to resolve them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Status: Available No one has claimed responsibility for resolving this issue.
Projects
None yet
Development

No branches or pull requests

3 participants