Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

1.02 still detected as malware #11

Closed
r-lyeh opened this issue Mar 7, 2025 · 10 comments
Closed

1.02 still detected as malware #11

r-lyeh opened this issue Mar 7, 2025 · 10 comments

Comments

@r-lyeh
Copy link
Owner

r-lyeh commented Mar 7, 2025

found here:

#10 (comment)

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 7, 2025

sadly, submitting the file to https://www.microsoft.com/en-us/wdsi/filesubmission did not make any difference,
so I've had to be more imaginative... this binary takes a different approach.
can you test this binary @Hexaae?

Spectral-wip.zip

@Hexaae
Copy link

Hexaae commented Mar 7, 2025

still blocked :(

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 7, 2025

odd, virustotal has not been triggering Defender nor Chrome threats since 1.02
not sure where the signature heuristics are coming from. maybe the binary is just not digitally signed ($$$) and that is all

@Hexaae
Copy link

Hexaae commented Mar 7, 2025

Yeah, it can be the heuristics AI...
Possibly paranoid because the emu connects online and downloads games automatically.

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 7, 2025

yeah, 4 kib downloads... so "dangerous" lol must be encrypted viruses!
sadly, it is much "safer" to download a 300 MiB task organizer .exe written in nodejs these days, sigh... /s/

@Hexaae
Copy link

Hexaae commented Mar 7, 2025

wondering how other similar apps do... Maybe you can get some advice from https://stackoverflow.com/ or SuperUser ?

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 7, 2025

@Korb has found https://SignPath.io which apparently does digital signatures for free on FOSS projects
the only catches are:
a) the validation of any FOSS project is probably subjective and human prone, not automated. not sure whether emulators or Spectral are valid candidates for them, even if the project is 101% FOSS. they seem to support big corps mostly?
b) it requires GitHub to build & sign the binaries so that also implies a more complete CI/CD workflow

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 7, 2025

that being said, maybe github CI is already "whitelisted" for Defender and such, so maybe their binaries are already valid out of the box?
I'm not sure, so i might give that a try, without the signpath signatures at all

Edit: well, that didnt work either

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 25, 2025

please check out the Spectral 105-RC beta

@r-lyeh
Copy link
Owner Author

r-lyeh commented Mar 25, 2025

fixed since v1.041

@r-lyeh r-lyeh closed this as completed Mar 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants