[clamav-users] FP on OWASP Dependency Check as Java.Malware.Agent-6297845-0:73

Al Varnell alvarnell at mac.com
Mon Oct 9 21:05:05 UTC 2017


If you have not done so already, you need to upload "dependency-check-core-1.4.5.jar" to <http://www.clamav.net/reports/fp <http://www.clamav.net/reports/fp>>

-Al-

On Mon, Oct 09, 2017 at 11:47 AM, Shaw Terwilliger wrote:
> Java.Malware.Agent-6297845-0:73 matches a file that's part of the
> OWASP Dependency Check tool, dependency-check-core-1.4.5.jar.
> 
>  bbeddbad91868290103ed3990e8e0276:515130:Java.Malware.Agent-6297845-0:73
> 
> The official repository versions of the files can be found at:
> 
>  https://repo.maven.apache.org/maven2/org/owasp/dependency-check-core/1.4.5 <https://repo.maven.apache.org/maven2/org/owasp/dependency-check-core/1.4.5>
> 
> As far as I know there isn't any malware inside this JAR, and the
> OWASP team hasn't published any vulnerabilities or retractions for
> that release.  Seems like a false positive match.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3569 bytes
Desc: not available
URL: <https://lists.clamav.net/pipermail/clamav-users/attachments/20171009/9c7651af/attachment.bin>


More information about the clamav-users mailing list