As I’m fed up with Google’s false positives on some of my tools on DidierStevens.com, I’m moving them to a new GitHub repository: FalsePositives.
FYI, here is their User Agent String:
Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US) AppEngine-Google; (+http://code.google.com/appengine; appid: s~virustotalcloud)
Today I was so surprised to see Windows Defender detected xorsearch.exe as Trojan. I had to reverse-engineer the binary to make sure it wasn’t any viral infection or supply-chains attack.
The binary is clean and a lot of XOR activities may have tripped many wires for auto-detection on anti-virus product.
@unixfreaxjp
Comment by ☩MalwareMustDie (@MalwareMustDie) — Monday 7 December 2020 @ 8:08