Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

McAfee reported trojan Artemis with klink.exe within build v0.73.2.2 zip #105

Closed
miaXcova opened this issue Jan 31, 2020 · 13 comments
Closed

Comments

@miaXcova
Copy link

I downloaded and extracted kitty-bin-0.73.2.2.zip from the following git page:
https://github.com/cyd01/KiTTY/releases

After the file was extracted, I received the following warning by McAfee Endpoint Security:
image

Below is from the McAfee log Please let me know if I can provide more details.

Analyzer / Detector

Analyzer content creation date | 1/30/2020 8:21 AM
Product name | McAfee Endpoint Security
Product version | 10.6.1
McAfee GTI query | Yes
Task name | On-Access Scan
Feature name | On-Access Scan
 
Threat
Action taken | Delete
Threat category | Malware detected
Threat detected on creation | Yes
Threat event ID | 1027
Threat handled | Yes
Threat name | Artemis!DA8C95003384
Threat severity | Critical
Threat timestamp | 1/31/2020 1:50 PM
Threat type | Trojan
 
Source
Source hostName | xxx
Source process name | C:\Windows\explorer.exe
 
Target
Target access time | 1/31/2020 1:49 PM
Target create time | 1/29/2020 8:45 AM
Target file size (bytes) | 310784
Target hash | da8c950033845dadbe3dd68e0c8c8e92
Target host name | xxx
Target modify time | 1/31/2020 1:49 PM
Target name | klink.exe
Target path | D:\Downloads\KiTTY\v0.73.2.2
Target user name | xxx\xxx
 
Other
Vector type | Local System
Cleanable | Yes
Detection message | McAfee Endpoint Security detected a threat.
Detection quarantine ID | {246A86AA-3933-4039-BA3F-2B725B9BCFCD}
Duration before detection (days) | 0
Description | xxx\xxxran C:\Windows\explorer.exe, which attempted to access D:\Downloads\KiTTY\v0.73.2.2\klink.exe. The Trojan named Artemis!DA8C95003384 was detected and deleted.
First action status | Succeeded
First attempted action | Clean
Second action status | Failed
Second attempted action | Delete
 

@zoltan-kecskemethy-epam
Copy link

Same here using Windows Security
Threat detected: Trojan:Win32/Detplock
Alert level: Severe
Date: 2/6/2020 10:14 PM
Category: Trojan
Details: This program is dangerous and executes commands from an attacker.
Affected items: ...\klink.exe
Learn more:
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3aWin32%2fDetplock&threatid=2147680291

@bobvandevijver
Copy link

Also happens with v0.73.2.3 of the kitty.exe file.

@bersbersbers
Copy link

bersbersbers commented Feb 12, 2020

3 out of 70 engines at VirusTotal.com detect it as malicious, the others don't:
https://www.virustotal.com/gui/file/dd6bb61464beee6787ff01b0eb35505b1aead6fa8aa910fe67a179435158109c/detection

@zoltan-kecskemethy-epam

Thanks @bersbersbers but I prefer to use the original release file links for the check instead of file upload. See latest files has no issues.
https://www.virustotal.com/gui/url/59e45edef552ab67db9e741c6f46ae5877ffb13cd903f6c554005164c2664177/details
https://www.virustotal.com/gui/url/7939dacfa47863824a785ee9d973bb0dbac0eddb5134f4b1c80d5d2b3245e0cb/detection

I confirm I've updated to latest release https://github.com/cyd01/KiTTY/releases/tag/v0.73.2.3 and
Windows security reports no issues.

@bobvandevijver
Copy link

bobvandevijver commented Feb 12, 2020

@kecskemethy Interesting, it is still marked by Windows here. The uncompressed version is not marked as unsafe, just as the locally build version.

@zoltan-kecskemethy-epam
Copy link

zoltan-kecskemethy-epam commented Feb 12, 2020

image
This is my win sec version @bobvandevijver no issue here for any of the files.

@bersbersbers
Copy link

bersbersbers commented Feb 12, 2020

@kecskemethy:

Thanks @bersbersbers but I prefer to use the original release file links for the check instead of file upload. See latest files has no issues.
https://www.virustotal.com/gui/url/59e45edef552ab67db9e741c6f46ae5877ffb13cd903f6c554005164c2664177/details

The latest file still has issues, you just have to make sure you look in the right place:

When I visit this URL, and click Details, and click the SHA-256 body value, which is

dd6bb61464beee6787ff01b0eb35505b1aead6fa8aa910fe67a179435158109c

I arrive at
https://www.virustotal.com/gui/file/dd6bb61464beee6787ff01b0eb35505b1aead6fa8aa910fe67a179435158109c/details
which is the URL I have posted. I have rescanned a minute ago and still,

2 engines detected this file:

Microsoft
Trojan:Win32/Detplock

Trapmine
Malicious.moderate.ml.score

I don't believe this is fixed yet. I rather think your URL scanner scans the URL, but not the body, so you think the body is fine while it's not.

By the way, now Chrome starts nagging about the security of kitty.exe downloads, too.

@TB-archIT
Copy link

I can confirm that kitty.exe (release 0.73.2.3) is declared as malware (trojan) by "McAfee Endpoint Security" a few minutes ago.

@AntonOks
Copy link

"Windows Defender" kicks the 0.73.2.3 kitty.exe now as a "Trojan_Win32/Wacatac.C!ml"
Never had virus problems with the previous KiTTY versions so far, but now I lost my favorite and life saver tool....

@zoltan-kecskemethy-epam

Yes I stand corrected @bersbersbers Thanks for taking time and fixing me.

Also I have the same issue now as reported above cannot use Kitty anymore. :(

@duracell
Copy link

There are 17 now and the /url/ links are not that helpful, because this checks only if the URL itself is in a blacklist and not if the file itself is detected as a virus.
I just thought your website was hacked because of the strange link to the /url/ virus total site and the alert from my system.

@rctgamer3
Copy link

@miaXcova
Copy link
Author

miaXcova commented Mar 1, 2020

I can confirm that v0.73.2.4 no longer erroneously triggers McAfee Endpoint Security. Thanks for staying on top of this guys. Closing.
image

@miaXcova miaXcova closed this as completed Mar 1, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

8 participants