False positive request for Charity Engine

Reply
Highlighted
L1 Bithead

False positive request for Charity Engine

Hello,

 

I'd like to request a review of the following file, which users running Traps have notified us as being flagged as Generic.ml, though no other engine on VirusTotal detects it as malicious:

 

File Hash:6963415f6681a2f5cff8ef1494b7dc85924a95cb5066425943e88107bc433a7d
Link to Virustotal report for the file:https://www.virustotal.com/gui/file/6963415f6681a2f5cff8ef1494b7dc85924a95cb5066425943e88107bc433a7d...
Current VirusTotal Verdict:Generic.ml (1/70)
Description:ce11-2019110801-windows_x86_64.exe is one of a variety of applications that members of the Charity Engine distributed computing pool download and run in order to participate in solving complicated tasks too difficult for any one system to solve on its own. These tasks range from charitable scientific research to commercial endeavors. On recent popular example is in solving the very last "Sum of three cubes" problem for 42, a mathematical riddle that had remained unsolved for 65 years (see https://phys.org/news/2019-09-sum-cubes-solvedusing-real-life.html if interested).

 

Thank you for your help --

 

Tristan


Accepted Solutions
Highlighted
L5 Sessionator

Re: False positive request for Charity Engine

This file looks to have checked for its IP address using IP checking websites, this action is common to malicious software. 

Also Http request without User-Agent among a few other suspicious actions these add up to high enough to give teh file a malicious verdict. 

View solution in original post


All Replies
Highlighted
L1 Bithead

Re: False positive request for Charity Engine

The false positive has been fixed, thank you. Is there something we can do for future applications to make them more trusted or otherwise less likely to be labeled as malware? We do digitally sign them already. Thanks again for your help.

Highlighted
L5 Sessionator

Re: False positive request for Charity Engine

This file looks to have checked for its IP address using IP checking websites, this action is common to malicious software. 

Also Http request without User-Agent among a few other suspicious actions these add up to high enough to give teh file a malicious verdict. 

View solution in original post

Highlighted
L1 Bithead

Re: False positive request for Charity Engine

That's great insight to have -- much appreciated, thank you!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!