Skip to content

Hollows Hunter: False positives or not? #81

Answered by hasherezade
tadev asked this question in Q&A
Discussion options

You must be logged in to vote

Hi! Sure it is a good place to ask such questions, and you are most welcome!

I reviewed your files briefly, and they look to me legitimate, yet they do have some anomalies that make them look malware-like for some products. The fact that reinstalling the product didn't help, only support this. For the second set of files, I also see that some (yet lesser) AV products again detected it as Meterpreter (i.e. Kaspersky here ) so it must contain something that trigger this pattern, yet I would assume it is a false positive.

Regarding PE-sieve/HollowsHunter - I can tell you what exactly was the feature that triggered the detection if you can upload the JSON reports in addition to the detected s…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@tadev
Comment options

@hasherezade
Comment options

Answer selected by tadev
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants