Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

xkbcomp.exe binary matching malware fingerprints #23

Open
A1kmm opened this issue Jul 29, 2024 · 0 comments
Open

xkbcomp.exe binary matching malware fingerprints #23

A1kmm opened this issue Jul 29, 2024 · 0 comments

Comments

@A1kmm
Copy link

A1kmm commented Jul 29, 2024

It looks like both xkbcomp.exe from both 21.1.13.0 and 21.1.10.0 (as downloaded from GitHub Releases) are getting detected as the "Gen:Variant.Lazy.574856" malware by multiple AV vendors. https://hybrid-analysis.com/sample/5e76de6e07913392c7f5d20a0b63305744c784bf1743a2b1c36e5dc9a7ba35e9 is an example showing this.

This seems to be a result of the AV vendors changing, rather than vcxsrv changing - however, it causes problems for vcxsrv, since these systems typically quarantine xkbcomp.exe, stopping vcxsrv from starting successfully.

I'm not sure exactly what it is that causes the signature match, so this might take some experimentation to find out what specifically causes it (unless the AV vendors make their detections more specific).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant