google / grr

GRR Rapid Response: remote live forensics for incident response

Home Page:https://grr-doc.readthedocs.io/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

It was detected a Trojan by Windows Defender

ta-b0 opened this issue · comments

commented

Hi.
I try to download it in Windows 10 (Latest Version).
However, Windows Defender was detected a Trojan(Trojan: Win32/Occamy.AA) in "grr-3.4.2.0-release.zip" when I download it.
I want to check this problem.
====(Windows Defender Log)====

Affected items:
containerfile: C:\Users\<UserName>\Downloads\grr-3.4.2.0-release.zip
file: C:\Users\<UsesrName>\Downloads\grr-3.4.2.0-release.zip->grr-3.4.2.0-release/grr/test/grr_response_test/test_data/win_hello.exe
webfile: C:\Users\<UserName>\Downloads\grr-3.4.2.0-release.zip|https://codeload.github.com/google/grr/zip/v3.4.2.0-release|pid:37756,ProcessStart:132433273045889314

win_hello.exe is a little Windows binary that we've compiled 6.5 years ago. The file got renamed and moved multiple times, but haven't changed since then. All it does is that it outputs "hello".

Please note this binary is a part of the grr_response_test package so it is not meant for any kind of production use. As for the Windows Defender alert - the binary obviously matches one of Windows Defender signatures - I'm not sure why. This looks as a false positive to me.

commented

Thank you for your information!