Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mod is being marked as a virus via BitDefender #25

Closed
Treazul opened this issue May 9, 2024 · 15 comments
Closed

Mod is being marked as a virus via BitDefender #25

Treazul opened this issue May 9, 2024 · 15 comments

Comments

@Treazul
Copy link

Treazul commented May 9, 2024

Upon running a modpack with this mod bitdefender has marked it as infected
The file D:\ATLauncher\instances\TerraFirmaGreg\mods\Ksyxis-1.2.2.jar is infected with Trojan.GenericKD.72678267 and was moved to quarantine. It is recommended that you run a System Scan to make sure your system is clean.

@VidTu
Copy link
Owner

VidTu commented May 9, 2024

skull

@Treazul
Copy link
Author

Treazul commented May 9, 2024

k

@Treazul Treazul closed this as completed May 9, 2024
@VidTu
Copy link
Owner

VidTu commented May 10, 2024

@Treazul either your specific JAR is infected, your PC is infected with something else or you're getting man-in-the-middle-attacked: https://www.virustotal.com/gui/file/8e97bb392718099d54377738a3501284eef98fbd54f6b46b4350fc9267ef4d47

@Treazul
Copy link
Author

Treazul commented May 10, 2024 via email

@Treazul
Copy link
Author

Treazul commented May 10, 2024 via email

@Treazul
Copy link
Author

Treazul commented May 10, 2024 via email

@VidTu
Copy link
Owner

VidTu commented May 10, 2024

for fs sake, what they don't like

@VidTu VidTu pinned this issue May 10, 2024
@VidTu
Copy link
Owner

VidTu commented May 10, 2024

maybe they don't like the way it uses a lot of method injections like here for multiversion support

@VidTu VidTu reopened this May 10, 2024
@VidTu
Copy link
Owner

VidTu commented May 10, 2024

what's funny, the latest gh actions snapshot is not being detected (even after reanalyzing) by any vendor

@Dorrivix
Copy link

Dorrivix commented May 13, 2024

*got this on mod version 1.2.2, the file extension isn't .jar, it's .bNIhAX

the full file my av shows is Ksyxis-1,2,2,jar.bNIhAX

download method: modpack via prism launcher, downloading from modrinth.

trying to download the mod again seems to end with a random string as the file extension, not just ".bNlhAX"

my AV is called "Vipre".

@VidTu
Copy link
Owner

VidTu commented May 13, 2024

@Dorrivix it seems like your antimalware renames it

@Dorrivix
Copy link

Dorrivix commented May 13, 2024

it doesn't trigger with downloading version 1.2.1

@VidTu
Copy link
Owner

VidTu commented May 13, 2024

well it also doesn't with 1.2.3-SNAPSHOT, you can reverse engineer 1.2.2 JAR and find nothing there. it was probably incorporated in some bigger malware (such as infected Minecraft modpack) and now antimalware flags it. i will not update JAR until I'll add 1.20.5 compat in a few days.

@VidTu
Copy link
Owner

VidTu commented May 20, 2024

hopefully fixed in 1.3.0.

@VidTu VidTu closed this as completed May 20, 2024
@VidTu
Copy link
Owner

VidTu commented May 23, 2024

BitDefender no longer flags 1.2.2 as infected, other vendors should follow shortly

@VidTu VidTu unpinned this issue May 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants