Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Virus detected in Windows version #3518

Closed
PKizzle opened this issue Apr 16, 2024 · 6 comments
Closed

Virus detected in Windows version #3518

PKizzle opened this issue Apr 16, 2024 · 6 comments
Labels
distribution Something related to the packaged binaries, app-images and installers os:windows The Windows platform

Comments

@PKizzle
Copy link

PKizzle commented Apr 16, 2024

Cortex XDR by Palo Alto Networks detects the Windows version of GitButler as virus.
Do you have any idea what might be causing this and how to prevent this in future releases?
Currently both version 0.11.1 and the nightly builds are affected.

Component: WildFire
Cortex XDR code: C0400055
Hash: c76d86368be3331901ab4371c8e497734eaacf7f76a2967cf3bf1054c2081993

@StarrrLiteNL
Copy link

StarrrLiteNL commented Apr 17, 2024

I got the same message for Avast. It looks like it tripped the generic heuristic detection, not a specific known threat database hit.
I have reported it as false positive with them , linking to this github repository.

Avast marked it as:
Other:Malware-gen [Trj]

Virustotal did not find anything in the installer; https://www.virustotal.com/gui/file/831d998b22e317acd48c7184acef8b5b89c825717d16545e7b83f3d7f9f5bdbb

It looks like the false positive is limited to Avast and Cortex XDR (perhaps they use the same detection engine?)

@schacon
Copy link
Member

schacon commented Apr 17, 2024

I submitted a false positive to Avast, but I'm not sure how to do so with Cortex.

@evgarthub
Copy link

same here, windows defender
image

@schacon
Copy link
Member

schacon commented Apr 17, 2024

This is a pretty fun game of Whack-a-Mole. I have submitted 11.0, 11.1 and now 11.2 to their upload thing. I don't know how anyone is supposed to do this or when they'll learn. I guess wait a few hours until they mark 11.2 as also not malware. God.

@PKizzle
Copy link
Author

PKizzle commented Apr 18, 2024

I reported it in the Palo Alto live community. Let's hope someone actually reads all of these threads.
Here is the link for reference: https://live.paloaltonetworks.com/t5/virustotal/false-positive-gitbutler/m-p/584220#M2438

@Byron Byron added os:windows The Windows platform distribution Something related to the packaged binaries, app-images and installers labels Apr 23, 2024
@Qix-
Copy link
Contributor

Qix- commented Apr 30, 2024

Hi all, going to close this for now as we have started submitting these false-positives to vendors directly (much to our discomfort). We haven't heard of any new cases of this for a few weeks so I'm going to take the brave assumption most have been squashed.

If you happen to get another false-positive, please open a new issue with your AV's name and any error messages / paths you can find from the detection event. For example, it's important for us to know if it is picking up the .MSI installer vs. one of the unpacked binaries (e.g. gitbutler-git-askpass.exe, etc).

Thanks for the reports everyone!

@Qix- Qix- closed this as completed Apr 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
distribution Something related to the packaged binaries, app-images and installers os:windows The Windows platform
Projects
None yet
Development

No branches or pull requests

6 participants