Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Detected: Trojan:Win32/Caynamer.A!ml inside of https://dragokas.com/tools/HiJackThis.zip #212

Closed
sync0x opened this issue Jun 4, 2023 · 5 comments

Comments

@sync0x
Copy link

sync0x commented Jun 4, 2023

Describe the bug
Windows defender reports the latest binary distribution of this utility to contain "Caynamer.A!ml" which I do not consent to receive.

To Reproduce
link in root page of this github project:
Pre-built binary (release version) for Windows
$ sha256sum HiJackThis.zip
7356f5f3b73a7d81ee8a6d3597fc362f0241cf5665cdb4360e79a980bc540060 *HiJackThis.zip

Expected behavior
Neither windows defender nor my choice of commercial antivirus scanner should detect remote access utilities. This defeats the purpose of which I have downloaded this utility product in the first place.

Screenshots
Detected: Trojan:Win32/Caynamer.A!ml
Date: 4/06/2023 3:43 PM
Affected Items:
file: C:\Users________\Downloads\HiJackThis\HiJackThis.exe

Desktop (please complete the following information):

  • OS: Windows 10
  • Version: 22H2 (19045.2965)

Additional context
It is one thing for you to give us the middle finger for the bombs flying around in your country. If you feel the need to stab us in the back while seeking legitimate solutions to our own security predicaments, to you I say thanks for validating some of the words that are coming out of Dr Evil's mouth. I would have hoped that pure thug had some intolerable provocation behind the dumbest decision of his life, to green light the willful aggression of his Organic Minions of SkyNet.

Thank you for being so willing to not only receive these munitions of which you refer to but to also go on the equivalent of a fundraising drive for them like your lives literally depended on them.

You do not get to allow systemic racism and the organized crime that perpetuates it to fester in your country without consequence. Not even the British nor the Americans can indulge in mob like activities without consequence, as they have learned from me recently.

If you want to look down upon us for our technological predicaments, unaware of the rationale for having our systems designed this way, maybe we ought to concede to the annexation demands levied against you on the basis of corruption which is becoming increasingly evident, and we shall see how you like being betrayed for standing up for yourselves.

I am reporting this exploit as an act of intentional abuse from this project.

@sync0x sync0x added the bug label Jun 4, 2023
@dragokas
Copy link
Owner

dragokas commented Jun 4, 2023

sync0x, about your political attacks - you messed up something: please, kindly read again the manifest in the description of the project (4th sentence to be exact), which was there for over 8 years in more or less the same form. I don't support British, Americans, weapon, attacks on Crimea, or attacks on Ukraine from anywhere. Where under Ukraine I mean adequate Ukrainian people, not a government, or territory.

As about second part: if you're speaking bad about americans, why do you use its protection? Use normal antiviruses which doesn't say bad about my tool (current version 3.0.0.4): https://www.virustotal.com/gui/file/27e90d829e382c8276b0678aaff3efaa40715bc10048619a88db4505dcf12a92
Also, you can help removing detection by sending false positive request to one of emails we constantly update and prepared here: https://www.safezone.cc/threads/kuda-soobschit-o-lozhnom-srabatyvanii-antivirusa.23501/
You don't even imagine how lot of time required to be wasted for this kind of task. I emphasize a free time, because nobody care to donate to the project, or help contributing code or translation. It's completely a hobby. If I don't feel like it's helpful to someone, or that it's hurting me, I stop and I may not work on the project for a whole year.

Even more, because of f*king EU certificate authorities who doesn't want to clean up personal data from the certificate violating UE GDPR and our local laws, I refused to sign software with a legal certificate. This thing strengthens the suspicion of antiviruses even more. I can do one of two things: stop development and waste my time for dealing with emails to AV vendors, wait 1 month or more, then update software and again waste time for AV, or I can just focus on development. Well, there is another option: not doing anything at all.

And third, it is open source (unlike most of AV utilities), anybody can compile it himself (the instruction is clear) and ensure that the antivirus detection will be the same. Anybody can press "Commits" button => "Compare commit details" => and verify which one changes were made.

And the last: it's for understanding the quality of nowadays antiviruses - here is a file I compiled with zero lines of code which doing nothing, there only thing - the Microsoft signed file is included in resources:
https://www.virustotal.com/gui/file/cc4afffa13b57c41be87a3a3c134f268c82a58951f9ad4563b8420edb9dbce9b/detection

And of course duplicate of existing issue: #22

@dragokas dragokas added enhancement and removed bug labels Jun 4, 2023
@dragokas
Copy link
Owner

dragokas commented Jun 4, 2023

Wasted whole the day to figure out which part of code Antiviruses don't like this time, and to send false reports in AV labs.
This update is specially for you:
https://www.virustotal.com/gui/file/220859a0e25f8c9796bcb68a691be892f4044e6ae5bdc7fa4bbb3493dad872d6?nocache=1

[3.0.0.6 Alpha] - June 04, 2023
- Fight against false antivirus detections:
	* Encrypted strings with Windows Defender keys
	* Rollback of CopyBytes optimization because Avira doesn't like this function :(
	* Temporarily moved to legit certificate which almost out-of-date
 - GitHub release link is replaced by static to a stable version 2.x, which will not be updated.

Please, report is everything OK right now.
Release and Test links are now point to different versions:

  • Release => outdated and stable 2.x
  • Test => new and often updated version 3.x

@dragokas
Copy link
Owner

dragokas commented Jun 6, 2023

@sync0x Microsoft removed detection from HJT+ v.3.0.0.4 as referred in you post:
https://www.virustotal.com/gui/file/27e90d829e382c8276b0678aaff3efaa40715bc10048619a88db4505dcf12a92/detection
Waiting for your apology.

As about quality of antiviruses:
image

There were only 3 detections at the time of your post.
You may compare detection names and clearly see which AV steal detections (or uses someone else's engine).
E.g. Cayunamer - it was a name given by Microsoft which is now not in list.
So, you must understand how hard to remove false positives. It's only a single version. If I recompile application again, most of those detections will re-appear again regardless the file is previously reported. And that's the issue any single developer face with, when the codebase is actively updated, especially for such "suspicious" type of software as malware scanner.

@sync0x
Copy link
Author

sync0x commented Jun 6, 2023 via email

@dragokas
Copy link
Owner

dragokas commented Jun 6, 2023

Topic is closed.
Reason: Topic starter is paranoid, does not admit his mistakes, and not responsible for his words.

@dragokas dragokas closed this as completed Jun 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants