Repository navigation
False Positive Alert: dsh-latest-windows-x64.exe flagged by SecureAge on VirusTotal #8731
Replies: 4 comments
误报的处置有标准流程——请补两样,我可以告诉你它落在哪一步1. 请补两样
2. 标准处置三步(建议照这个提)
3. 建议的诉求(写给发布方,可判定)
4. 一条边界我没有该安装包,也无法复现杀软行为。⇒ 本条的价值在**"把误报变成可走流程"**;第 1 节两样齐了就能推进。 |
|
Thanks for this direction. Here are the information you have asked:
Virus Total report: Maintainers: can someone confirm the real SHA-256 for this release and if yes, submit it as false-positive to Secure Age? Thanks again. |
你给的材料已经足够提交误报了——而且不必等维护者1. 你这份证据是"误报"的最强形态
⇒ 建议把 VirusTotal 那句放在摘要第一句("1/50,仅 SecureAge")——它比任何描述都更能让厂商与读者判断。 2. ⇒ 不必等维护者:用户也可以提交误报误报申诉通常对任何提交者开放(不需要是项目维护者)。⇒ 你现在就可以做:
⇒ 这条能今天就推进,而"等维护者确认哈希"会把它卡住。 3. 但"官方哈希"仍然值得要(
|
|
Thanks for the clarification. I actually deleted the original .exe once I had tested it, so I no longer have the specific file that created the Virus Total result. I'll retreive the Windows binary from DeepSeek's official page, compute its sha-256 hash with Power Shell, and check it against this reported value: d61cd8882f8b8a1251144320493ad27920d15139503eba2465b9579eee720cfc If the hash is the same I will upload that binary to Secure Age along with the Virus Total report and source of download. If the hash is different, then I will call it a different build rather than the same file. I'll also still ask maintainers to provide a published official checksum of the binary, so that users can verify it for themselves. |
Uh oh!
There was an error while loading. Please reload this page.
Hi team,
For reference, I was about to report about the false positive security flag on the latest windows build When I launched the dsh-latest-windows-x64.exe installer it flagged a security alert on Virus Total from one of the vendors.
Below is the date/time of the file analysis:
File Name: dsh-latest-windows-x64.exe
File Hash: d61cd8882f8b8a1251144320493ad27920d15139503eba2465b9579eee720cfc
Detection Score: 1/50 security vendors identified this file as malicious.
Flagging Vendor: Secure Age (marked as Malicious)
Other vendors' status: All other major vendors (Crowd Strike Falcon, Microsoft, Avira, Kaspersky, etc.) have marked the file as Undetected.
Because only a single engine (Secure Age) detects this, this seems almost certainly to be a false positive, perhaps because the application is not signed, or packed in a way that causes heuristic scans to alert.
Can the maintainers please consider white-listing and/or submitting a false positive report to Secure Age? Also, is there anything particular to the components or network behaviors in the harness that would be causing this so we can document for others so they're not concerned when building or installing.
Thanks for the awesome job on this tool!

All reactions