FP Report on BA003.exe (md5 5fcec23f3a287e118af4a73966dc796d)

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

FP Report on BA003.exe (md5 5fcec23f3a287e118af4a73966dc796d)

L0 Member
Hi PaloAlto, One of our files, BA003.exe (md5 5fcec23f3a287e118af4a73966dc796d) is being flagged as generic.ml. Can I ask you to review and reassess the detected file in the context of the installer that uses the file, rather than as a stand-alone file, with the aim of removing BA003.exe from detection? Detected file and installer can be downloaded from hxxps://www.dropbox.com/s/u0mvnk5chxhojvw/20180614-BA003-PaloAltoDetections.7z?dl=0. Archive password: infected Thanks, Andrew Browne Director, Malware Labs Adaware

L5 Sessionator

Hello LS_Andy,


Can you please post the SHA256 of the files you wish to have evaluated, I can not download files from dropbox.

Hi dparris,


Thanks for getting back to me.


BA003.exe (detected file)



trueburner_4.9.exe (installer that calls the detected file)

I have added your hashes for reassessment. 

L4 Transporter

The verdict for these samples is now benign so there should be no further issues with them.

  • 4 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!