Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AV engines false positives on orbit.exe #5049

Closed
lucasmrod opened this issue Apr 11, 2022 · 8 comments
Closed

AV engines false positives on orbit.exe #5049

lucasmrod opened this issue Apr 11, 2022 · 8 comments
Assignees
Labels
~backend Backend-related issue. bug Something isn't working as documented :reproduce Involves documenting reproduction steps in the issue
Milestone

Comments

@lucasmrod
Copy link
Member

Orbit version: 0.0.8

Operating system: Windows (version TBD).

Kaspersky was removing the C:\Program Files\Orbit\bin\orbit\windows\stable\orbit.exe executable from hosts hence bringing them offline.

User report:

orbit.exe
Objects selected: Properties
Description:
Action:
Device: <redacted>
Status: Deleted
Object: UDS:Trojan-Downloader.Win32.Agent.xxzyee
Date of placement: 04-04-2022 7:12:45 AM
Size (bytes):
Path: C:\Program Files\Orbit\bin\orbit\windows\stable\orbit.exe
User: NT AUTHORITY\SYSTEM

More info

Slack thread: https://osquery.slack.com/archives/C01DXJL16D8/p1649225363306839

@lucasmrod lucasmrod added bug Something isn't working as documented :reproduce Involves documenting reproduction steps in the issue ~backend Backend-related issue. labels Apr 11, 2022
@zwass zwass self-assigned this Apr 11, 2022
@zwass
Copy link
Member

zwass commented Apr 11, 2022

VirusTotal for Orbit 0.0.8 - https://www.virustotal.com/gui/file/afb906512b19853c485697a2d6f3a725a3ae9fba1a0fe9a7b4ea11dd54dea6c2/detection

Surprisingly, this shows no detection from Kaspersky, but does show detections from a couple of other vendors.

@zwass
Copy link
Member

zwass commented Apr 11, 2022

It is detected on Kaspersky's own analysis page: https://opentip.kaspersky.com/AFB906512B19853C485697A2D6F3A725A3AE9FBA1A0FE9A7B4EA11DD54DEA6C2/

@zwass
Copy link
Member

zwass commented Apr 11, 2022

I submitted false positive reports to all of the offending vendors: Kaspersky, Cylance, MaxSecure, and Ikarus.

@zwass
Copy link
Member

zwass commented Apr 11, 2022

Kaspersky confirmed that it's a false positive and will be resolved on their end. I asked for a time estimate of how long this will take.

@zwass
Copy link
Member

zwass commented Apr 12, 2022

Kaspersky estimated it would be 2-3 hours for the update to take place. I've rechecked through their tool and it's now marked as "clean".

I did not receive any confirmation from Cylance, but it is no longer generating a false positive on recheck from VirusTotal.

@zwass zwass changed the title Kaspersky marking orbit.exe as trojan AV engines false positives on orbit.exe Apr 12, 2022
@zwass
Copy link
Member

zwass commented Apr 12, 2022

Ikarus confirmed the fix and it's no longer showing up on VirusTotal.

We got two new ones: Tencent (Win32.Trojan-downloader.Agent.Wsty) and Rising (Downloader.Agent!8.B23 (CLOUD)).

@zwass
Copy link
Member

zwass commented Apr 15, 2022

MaxSecure confirmed fix and it's no longer showing up on VirusTotal. So the original set of detections are now resolved.

Will need to make reports to Tencent and Rising.

@zwass
Copy link
Member

zwass commented Apr 18, 2022

Currently clean! I'm sure we'll find new issues in the future, but closing out this ticket for now.

Screen Shot 2022-04-18 at 10 20 56 AM

@zwass zwass closed this as completed Apr 18, 2022
@lukeheath lukeheath added this to the 4.13.0 milestone Apr 18, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
~backend Backend-related issue. bug Something isn't working as documented :reproduce Involves documenting reproduction steps in the issue
Development

No branches or pull requests

3 participants