False positive request for Charity Engine

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

False positive request for Charity Engine

L1 Bithead

Hello,

 

I'd like to request a review of the following file, which users running Traps have notified us as being flagged as Generic.ml, though no other engine on VirusTotal detects it as malicious:

 

File Hash:6963415f6681a2f5cff8ef1494b7dc85924a95cb5066425943e88107bc433a7d
Link to Virustotal report for the file:https://www.virustotal.com/gui/file/6963415f6681a2f5cff8ef1494b7dc85924a95cb5066425943e88107bc433a7d...
Current VirusTotal Verdict:Generic.ml (1/70)
Description:ce11-2019110801-windows_x86_64.exe is one of a variety of applications that members of the Charity Engine distributed computing pool download and run in order to participate in solving complicated tasks too difficult for any one system to solve on its own. These tasks range from charitable scientific research to commercial endeavors. On recent popular example is in solving the very last "Sum of three cubes" problem for 42, a mathematical riddle that had remained unsolved for 65 years (see https://phys.org/news/2019-09-sum-cubes-solvedusing-real-life.html if interested).

 

Thank you for your help --

 

Tristan

1 accepted solution

Accepted Solutions

This file looks to have checked for its IP address using IP checking websites, this action is common to malicious software. 

Also Http request without User-Agent among a few other suspicious actions these add up to high enough to give teh file a malicious verdict. 

View solution in original post

3 REPLIES 3

L1 Bithead

The false positive has been fixed, thank you. Is there something we can do for future applications to make them more trusted or otherwise less likely to be labeled as malware? We do digitally sign them already. Thanks again for your help.

This file looks to have checked for its IP address using IP checking websites, this action is common to malicious software. 

Also Http request without User-Agent among a few other suspicious actions these add up to high enough to give teh file a malicious verdict. 

That's great insight to have -- much appreciated, thank you!

  • 1 accepted solution
  • 3045 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!