Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

gisto flagged as malware by VirusTotal #310

Open
core-code opened this issue Apr 16, 2021 · 14 comments
Open

gisto flagged as malware by VirusTotal #310

core-code opened this issue Apr 16, 2021 · 14 comments

Comments

@sanusart
Copy link
Member

sanusart commented Apr 16, 2021 via email

@core-code
Copy link
Author

Gisto-1.13.4.dmg

@sanusart
Copy link
Member

sanusart commented Apr 16, 2021 via email

@core-code
Copy link
Author

weirdly if you upload the app inside the ZIP, its red again:
https://www.virustotal.com/gui/file/2b09c14becdfb2011665e758149cd59bd570c628305d79e3bea9a5402ec9525c/detection

@sanusart
Copy link
Member

sanusart commented Apr 18, 2021 via email

@core-code
Copy link
Author

don't think that could be the reason. i check thousands of apps every month with virustotal. about half of them are unsigned and its never been a problem.

@morsdyce
Copy link
Member

This is probably related to Electron being detected as malware incorrectly, you can see the following thread on atom with very similar issues:
atom/atom#3927

@coltjones
Copy link

I just got an alert about this being potential malware as well, though it came out of Carbon Black. Here are the details that I have on the issue.

The OS X version of the application has the following SHA256 hash:
SHA256(/Applications/Gisto.app/Contents/MacOS/Gisto)= a0c461c94ba9f1573c7253666d218b3343d24bfa5d8ef270ee9bc74b7856e492

Per the following CISA report, this hash is a signature of known maleware.
https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-048f

@sanusart
Copy link
Member

@coltjones thanks.
Where have you downloaded the app from? From here at GitHub?

@coltjones
Copy link

@sanusart
Copy link
Member

Still seems to be related to electron. Will try to update electron version.

@johntrandall
Copy link

johntrandall commented May 24, 2022

MacPaw's "Clean My Mac" app is identifying Gisto.app v1.13.4 as being infected with NukeSped Trojan.

@sanusart
Copy link
Member

sanusart commented Oct 11, 2022 via email

@617dev
Copy link

617dev commented Jun 9, 2023

My cyber security team identified a file within the Gisto package as known North Korean malware 😬 needless to say I had to remove it from my machine. I just wanted to note that installing gisto via homebrew will result in a package that still gets flagged in 2023.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants