Since Monday, we investigated a little further and found that the executable is extracted by the MPRESS unpacker a part of our bytecode.cvd signature set, and then once unpacked it alerted with the Win.Dropper.Tinba-9943147-0 signature. It makes sense that
if it could be unpacked with the MPRESS unpacker that it would also alert with the PUA.Win.Packer.Exe-6 signature. The reason that the Win.Dropper.Tinba-9943147-0 signature did not alert during the false positive report processing is because of a bug wherein
bytecode signatures will not run if a signature alert already occurred, even in all-match mode. I am working on a fix for this now, while I work on other improvements to the all-match feature.
Yaron,
For now, your application is instead added as a hash-based FP signature to our daily.cvd database to prevent the false positive. I would be curious to know if there is anything unusual in your application build process that would help me understand why ClamAV
thinks the application is packed using the MPRESS packer. I suspect that future builds of your application will have the same issue unless we are able to refine the detection or change how your software is built to prevent the detection.
Regards,
Micah
Micah Snyder
ClamAV Development
Talos
Cisco Systems, Inc.
From: clamav-users <clamav-users-bounces@lists.clamav.net> on behalf of Christopher Marczewski <cmarczewski@sourcefire.com>
Sent: Monday, July 11, 2022 4:48 PM
To: ClamAV users ML <clamav-users@lists.clamav.net>
Subject: Re: [clamav-users] False positive, My program is recently Started to be flagged with Win.Dropper.Tinba-9943147-0
Looks like allmatch scanning may be confined to the PUA CVDs if the first signature alert is a PUA signature, as was the case here.
PUA.Win.Packer.Exe-6 alerted on this sample during the report processing, but no additional signature alerted. A manual scan without PUA signatures enabled resulted in the expected FP hit.
I've dropped the signature after examining the binary and will check with the dev team on this case.
--
Christopher Marczewski
Research Engineer, Talos
Cisco Systems
443-832-2975