FP Report on BA003.exe (md5 5fcec23f3a287e118af4a73966dc796d)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

FP Report on BA003.exe (md5 5fcec23f3a287e118af4a73966dc796d)

L0 Member
Hi PaloAlto, One of our files, BA003.exe (md5 5fcec23f3a287e118af4a73966dc796d) is being flagged as generic.ml. Can I ask you to review and reassess the detected file in the context of the installer that uses the file, rather than as a stand-alone file, with the aim of removing BA003.exe from detection? Detected file and installer can be downloaded from hxxps://www.dropbox.com/s/u0mvnk5chxhojvw/20180614-BA003-PaloAltoDetections.7z?dl=0. Archive password: infected Thanks, Andrew Browne Director, Malware Labs Adaware
4 REPLIES 4

L5 Sessionator

Hello LS_Andy,

 

Can you please post the SHA256 of the files you wish to have evaluated, I can not download files from dropbox.

Hi dparris,

 

Thanks for getting back to me.

 

BA003.exe (detected file)

4b1210cdedc7601e1f2e4ddc12e42ea3e57bf389049f088b0fb7553bdb835ea5

 

trueburner_4.9.exe (installer that calls the detected file)
ac9bc0eeba287806898e1029d0a221ca5b702fd4c1eb08d82966ddfa6dc6a91a 

I have added your hashes for reassessment. 

L4 Transporter

The verdict for these samples is now benign so there should be no further issues with them.

  • 3454 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!