Skip to content

VirusTotal false positives (3/72 detections on unsigned build) #43

@amruth-alur

Description

@amruth-alur

Issue Description

The current release KeyEcho_0.0.5_arm64-setup.exe is triggering 3/72 detections on VirusTotal:

  • Arctic Wolf: Unsafe
  • DeepInstinct: MALICIOUS
  • SecureAge: Malicious

VirusTotal Link

https://www.virustotal.com/gui/file/f59331c16aafd343a935ab763e1984f58ae18910ff31b89e60de777369c7e5b3

Root Cause

The executable is unsigned, and keyboard hooking functionality triggers ML/heuristic engines.

Suggested Actions

  1. Consider code signing the releases (even with open-source certificates)
  2. Report false positives to affected vendors (links below)
  3. Document expected detections in README with verification instructions

False Positive Submission Links

I'm happy to help with false positive submissions if needed.

Keep up the good work Zachary! :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions