Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

19 engines detect OFscraper as virus now? #477

Open
Dark-Obsidian opened this issue Nov 26, 2024 · 6 comments
Open

19 engines detect OFscraper as virus now? #477

Dark-Obsidian opened this issue Nov 26, 2024 · 6 comments

Comments

@Dark-Obsidian
Copy link

Description

I was aware that previous versions of OFscraper are flagged by 1-2 engines on virustotal.com, however when I was updating to 3.12.9, my AV went off as it seems 19 engines now detect OFscraper as a trojan!?

To Reproduce

Expected behavior

  • AV engines do not flag OFscraper as trojan/virus
  • OFscraper does not get detected with suspicious activities such as:
    • XOR obfuscation
    • VM/detection evasion (Reference anti-VM strings targeting VirtualBox)
    • Hijack execution flow
       

Screenshots/Logs

OFscraper_detections

System Info

  • OS: Windows
  • Browser: Edge
  • Binary or python: Binary

Additional information

Not accusing OFscraper of being a trojan, but whatever code changes you have made recently seem to be sending AV engines crazy!

@Puk0
Copy link

Puk0 commented Nov 27, 2024

Zip exe...

2024-11-27 023317

@Dark-Obsidian
Copy link
Author

OK... but that's just putting the .exe inside a .zip file (making it harder for the engines to scan/detect)... If you password-protect the .zip file, you can get down to 0 detections.

@cjb900
Copy link

cjb900 commented Dec 4, 2024

While I can't answer what changes were made that are causing so many antivirus engines to detect it on virustotal. I and many others have been running this version for months now and no one has mentioned seeing any strange/malicious activity. The antivirus (Bitdefender) and hardware firewall (firewalla) I use myself have not picked up any malicious activity either. So while IMHO I don't think you have any cause for concern. But if you want to be safe then run this in a VM (VMware or VirtualBox) or on a spare computer (if you have one that is).

@Puk0
Copy link

Puk0 commented Dec 4, 2024

OK... but that's just putting the .exe inside a .zip file (making it harder for the engines to scan/detect)... If you password-protect the .zip file, you can get down to 0 detections.

In the zip version, if you unzip it and scan the exe, that result will appear.

Not that I compress it to scan it.

@datawhores
Copy link
Owner

datawhores commented Dec 4, 2024

The process for making the zip and exe are open. Look at the GitHub actions. You can make the zips or exe your self.

If you don't trust these processes. Then learn how to use git and install the program from repo.

The zip and exe are just meant as an easy way for newbies to install the script, and to reduce the amount of support required, but this and other issues in making them. Make me think it would be better to stop providing them.

@CynicalPlatapus
Copy link

That'd be a real shame, the exe is just so much more convenient for myself and others

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants