Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ssf-win-x86_64-3.0.0.zip is a trojan #94

Open
jtmoon79 opened this issue Apr 5, 2021 · 1 comment
Open

ssf-win-x86_64-3.0.0.zip is a trojan #94

jtmoon79 opened this issue Apr 5, 2021 · 1 comment

Comments

@jtmoon79
Copy link

jtmoon79 commented Apr 5, 2021

The download ssf-win-x86_64-3.0.0.zip appears to be a trojan.

https://www.virustotal.com/gui/file/329748f6ea665d1c398cc09f19cee5784d5356eaf8a49988c069d4bffbca9f26/detection

@jtmoon79 jtmoon79 changed the title this appears to be trojan ssf-win-x86_64-3.0.0.zip is a trojan Apr 5, 2021
@colemar
Copy link

colemar commented Nov 4, 2024

False positive or not, a detection ratio of 46/67 on VirusTotal is a problem.
It cannot be downloaded in Chrome nor in Firefox unless you force it. Even then, it does not stay long because it will be nuked by practically any decent antivirus.

If you manage to unzip it, the main offender seems upx-ssf.exe (VT detection ratio: 34/71):
image
UPX compression is popular among malware:
https://www.esecurityplanet.com/threats/upx-compression-detection-evasion/

All of the executables get high VT detection ratios.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants