Nmap Development mailing list archives

Re: Nmap 4.76 detected as a Trojan by BitDefender 2009


From: Fyodor <fyodor () insecure org>
Date: Mon, 2 Mar 2009 13:10:24 -0800

On Sun, Mar 01, 2009 at 07:20:12PM +0000, Brandon Enright wrote:
I just sent the whole installer to VirusTotal and the results are a
little less encouraging:

https://www.virustotal.com/analisis/9819a7c66664730b9911bbadd7d50f77

8 of then 39 products flag the installer with some heuristic.

Good find.  Interestingly, the newer nmap-4.85BETA3-setup.exe only has
1/37 flags (and that is the "corrupted archive" by Sunbelt):

http://www.virustotal.com/analisis/a9be2056e8d94963c4e9e8858b4c1678

In case this was due to signature updates since yesterday rather than
the different file, I ran it again against nmap-4.76-setup.exe:

http://www.virustotal.com/analisis/f62ab34ac2cd64d2ca49789fa843d72b

This time it shows 6/34 as flagged.  So the 4.85BETA installer really
does seem to be treated as more clean, for some reason.

Cheers,
-F

_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://SecLists.Org


Current thread: