WinDefender calling epyrus a C2 threat

Board for discussions around the Epyrus mail and news client.

Moderator: athenian200

Potkeny
Fanatic
Fanatic
Posts: 159
Joined: 2018-08-03, 17:00

WinDefender calling epyrus a C2 threat

Post by Potkeny » 2023-09-28, 17:45

I guess its another false-positive the usual way, anything I can do to make MS realize its not a threat?
windows_defender_alert.PNG
You do not have the required permissions to view the files attached to this post.

User avatar
Moonchild
Project founder
Project founder
Posts: 38922
Joined: 2011-08-28, 17:27
Location: Sweden

Re: WinDefender calling epyrus a C2 threat

Post by Moonchild » 2023-09-28, 18:34

Potkeny wrote:
2023-09-28, 17:45
anything I can do to make MS realize its not a threat?
Upload to virustotal and give it a vote of confidence. Since they bought it, etc.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Potkeny
Fanatic
Fanatic
Posts: 159
Joined: 2018-08-03, 17:00

Re: WinDefender calling epyrus a C2 threat

Post by Potkeny » 2023-09-28, 18:53

Thanks, found it based on hash, upvoted.

User avatar
athenian200
Contributing developer
Contributing developer
Posts: 1637
Joined: 2018-10-28, 19:56
Location: Georgia

Re: WinDefender calling epyrus a C2 threat

Post by athenian200 » 2023-09-28, 23:25

Yeah, basically this is what happens nowadays to developers who can't afford code signing... they are assumed to be hackers until proven innocent. :/
"The Athenians, however, represent the unity of these opposites; in them, mind or spirit has emerged from the Theban subjectivity without losing itself in the Spartan objectivity of ethical life. With the Athenians, the rights of the State and of the individual found as perfect a union as was possible at all at the level of the Greek spirit." -- Hegel's philosophy of Mind

Potkeny
Fanatic
Fanatic
Posts: 159
Joined: 2018-08-03, 17:00

Re: WinDefender calling epyrus a C2 threat

Post by Potkeny » 2023-10-06, 12:03

And now it's Trojan:Win32/Bearfoos.A!ml.. I guess I have to get used to Defender finding it a threat weekly unless I want to make an exception folder for it (which I don't really like).

User avatar
back2themoon
Knows the dark side
Knows the dark side
Posts: 3097
Joined: 2012-08-19, 20:32

Re: WinDefender calling epyrus a C2 threat

Post by back2themoon » 2023-10-06, 13:01

Potkeny wrote:
2023-10-06, 12:03
...which I don't really like....
Consider using better security software. Not just for this issue - as far as I know, Defender's web protection only fully works with Microsoft Edge, for example. And that's hardly its only weakness.

User avatar
Raava
Fanatic
Fanatic
Posts: 202
Joined: 2014-06-22, 22:23
Location: Europe

Re: WinDefender calling epyrus a C2 threat

Post by Raava » 2023-10-06, 17:13

Potkeny wrote:
2023-10-06, 12:03
And now it's Trojan:Win32/Bearfoos.A!ml.. I guess I have to get used to Defender finding it a threat weekly unless I want to make an exception folder for it (which I don't really like).
Can you upload it to https://virusscan.jotti.org/ ?
About Jotti's malware scan
Jotti's malware scan is a free service that lets you scan suspicious files with several anti-virus programs. You can submit up to 5 files at the same time. There is a 250MB limit per file. Please be aware that no security solution offers 100% protection, not even when it uses several anti-virus engines. All files are shared with anti-virus companies so detection accuracy of their anti-virus products can be improved.
Jotti uses 14 malware scanners, the best online malware scanning site via uploading files I know of. (I am not affiliated with virusscan.jotti.org in any way - I just like his approach, and I do so for many years)

I would be interested if the other scan engines are as dumb as WinDefender is.
yours truly, Rava

Potkeny
Fanatic
Fanatic
Posts: 159
Joined: 2018-08-03, 17:00

Re: WinDefender calling epyrus a C2 threat

Post by Potkeny » 2023-10-06, 17:57

You mean like virustotal with its collection of scanners?

https://www.virustotal.com/gui/file/fd9 ... 56ff2e7143

User avatar
Raava
Fanatic
Fanatic
Posts: 202
Joined: 2014-06-22, 22:23
Location: Europe

Re: WinDefender calling epyrus a C2 threat

Post by Raava » 2023-10-06, 18:35

Potkeny wrote:
2023-10-06, 17:57
You mean like virustotal with its collection of scanners?

https://www.virustotal.com/gui/file/fd9 ... 56ff2e7143

Indeed, very similar to that.
But your link puts heavy load on my browser (my machine has outdated hardware) while https://virusscan.jotti.org/ never does.
But I save your link aside my jotti one just in case I need it. :D (When in doubt, one can never have enough free malware scanners available.)
So, once more, thanks Potkeny .
yours truly, Rava

User avatar
moonbat
Knows the dark side
Knows the dark side
Posts: 5782
Joined: 2015-12-09, 15:45

Re: WinDefender calling epyrus a C2 threat

Post by moonbat » 2023-10-06, 22:10

Raava wrote:
2023-10-06, 18:35
When in doubt, one can never have enough free malware scanners available.
So long as you mean online ones. Installing multiple local ones will conflict and slow down your system even more among other potential problems. Windows since XP detects if you have a third party antivirus and will disable the built in MSE/Defender in response.
"One hosts to look them up, one DNS to find them and in the darkness BIND them."

Image
KDE Neon on a Slimbook Excalibur (Ryzen 7 8845HS, 64 GB RAM)
AutoPageColor|PermissionsPlus|PMPlayer|Pure URL|RecordRewind|TextFX
Jabber: moonbat@hot-chili.net

User avatar
Moonchild
Project founder
Project founder
Posts: 38922
Joined: 2011-08-28, 17:27
Location: Sweden

Re: WinDefender calling epyrus a C2 threat

Post by Moonchild » 2023-10-06, 23:47

Raava wrote:
2023-10-06, 18:35
But your link puts heavy load on my browser (my machine has outdated hardware) while https://virusscan.jotti.org/ never does.
Welcome to Google WebComponents.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Raava
Fanatic
Fanatic
Posts: 202
Joined: 2014-06-22, 22:23
Location: Europe

Re: WinDefender calling epyrus a C2 threat

Post by Raava » 2023-10-07, 03:08

moonbat wrote:
2023-10-06, 22:10
So long as you mean online ones. Installing multiple local ones will conflict and slow down your system even more among other potential problems.
I meant online ones only. But good you cleared that up for the benefit of potential lurkers.

And my sole OSes left nowadays are Linux variants, since the last Windoze broke itself on my last machine hosting one I saw no reason to repair or reinstall that since on average I started Windoze once a year for a very few hours only.
moonbat wrote:
2023-10-06, 22:10
Windows since XP detects if you have a third party antivirus and will disable the built in MSE/Defender in response.
As long MSE/Defender is the best and flawless malware scanner that is out there I see no issues with that.
Moonchild wrote:
2023-10-06, 23:47
Welcome to Google WebComponents.
Seems Google WebComponents is the pest and cholera of modern internet browsing. Thanks so much Gøøgle for that, much appreciated. *rolling eyes virtual head-desking*
yours truly, Rava

User avatar
Moonchild
Project founder
Project founder
Posts: 38922
Joined: 2011-08-28, 17:27
Location: Sweden

Re: WinDefender calling epyrus a C2 threat

Post by Moonchild » 2023-10-07, 08:20

Raava wrote:
2023-10-07, 03:08
Thanks so much Gøøgle for that, much appreciated.
To be fair, the frameworks jumping on using it are just as much at fault.
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite