Skip to content

Malware Detection - False Positive? test_upx.exe #12950

Closed Answered by dougburks
jdonovan1013 asked this question in 2.4
Discussion options

You must be logged in to vote

test_upx.exe is part of the Docker image for Strelka:

find / -name test_upx.exe
/var/lib/docker/overlay2/de691cd3ad63ce7c3118aa7774adadaf1535a6094b19a158ca2c1b42b4599374/diff/strelka/strelka/tests/fixtures/test_upx.exe
/var/lib/docker/overlay2/5a14f89ee4fbedd01e5309cd4087e160bda2faec951caa06296af2acaa85c5ff/diff/strelka/strelka/tests/fixtures/test_upx.exe

Here's the relevant sentence from https://docs.securityonion.net/en/2.4/download.html:

In some cases, the alert may be for a sample EXE that is included in Strelka but again a false positive.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@jdonovan1013
Comment options

Answer selected by dougburks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants