question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Trojan detected in FunctionReachabilityPlugin.class

See original GitHub issue

Description of the issue Please review the build process or investigate a false positive.

After downloading (with a Mac) and checking the SHA-256 sum, some anti-malware / antivirus tools detect Windows trojans in the class files. After unpacking the sources included, and once reviewed the detected class file corresponding source code, the source code seems to be ok.

To Reproduce

  1. Download the file ghidra_9.0_PUBLIC_20190228.zip.
  2. Check the SHA-256 sum (OK)
  3. Scan with free, up to date, anti-malware tool BitDefender (I’m using a Mac)
  4. A trojan “Java.Trojan.GenericGB.26094” is found in FunctionReachabilityPlugin.class

Expected behavior No (false nor true) trojan detections should be happening if the provided source code for that class was actually what was compiled.

Screenshots screen shot 2019-03-07 at 2 26 55 pm

Environment (please complete the following information):

  • OS: mac OS 10.14.3 (18D109)
  • Version: 9.0_PUBLIC_20190228

Issue Analytics

  • State:closed
  • Created 5 years ago
  • Comments:8

github_iconTop GitHub Comments

8reactions
dragonptcommented, Mar 7, 2019

I bet its an false positive… Surely something from NSA is trustable…

/irony

1reaction
gvisoccommented, Mar 11, 2019

I’ve been decompiling the class with different products over the weekend only to see the recognisable source code (@quosego I wasn’t able to properly build) and, besides, today the Bitdefender stopped reporting the file after an update (I was just checking the file again before reporting the false positive to Bitdefender).

I’m closing the issue @ryanmkurtz

Read more comments on GitHub >

github_iconTop Results From Across the Web

Trojan Virus Threat Detected: - Microsoft Community
I run Windows 10 Defender and it says "OKAY" with the Quick Scan, but the FULL Scan shows there are affected items. containerfile:...
Read more >
What Is Trojan Malware? The Ultimate Guide - Viruses - Avast
A Trojan is a nasty, sneaky type of malware that disguises itself as something harmless to fool you into installing it. Learn how...
Read more >
Understanding Trojan Viruses and How to Get Rid of Them
Trojan viruses are a type of malware that invade your computer ... the McAfee antivirus program can identify new trojans by detecting ......
Read more >
What Is a Trojan Horse Virus & How Do You Get Rid of It?
A Trojan virus on a computer, or simply a Trojan, is a malicious software program or code masquerading as legitimate and harmless software. ......
Read more >
What Is a Trojan Horse? Trojan Virus and Malware Explained
Its purpose is to stop malicious programs from being detected, which enables malware to remain active on an infected computer for a longer...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found