Hacking DevkitPro updater 2.0.0 Trojan.Win32:Occamy.B

NicknameGoesHere

RIP my sanity: 2018-2018
Member
Joined
Jul 11, 2017
Messages
243
Reaction score
23
Trophies
0
XP
251
Country
United States
When I install the devkitpro updater version 2.0.0, or i update a previous updater to 2.0.0, windows defender tells me I have Trojan.Win32:Occamy.B I've installed this updater version on other windows PC's before without problem. What's going on?
 
My devkitpro installer is still 1.6.0, and the official repo has the latest version being 1.7.0, so I'm unsure how you have 2.0.0
 
I can't check it with virustotal right now. Can you check it?

--------------------- MERGED ---------------------------

That was supposed to be sent a while ago.
 
CdjULQGnTFlRz8V0DBEhwmSHM7ck.png

https://virusscan.jotti.org/en-US/filescanjob/5vd1d0g8vu
https://metadefender.opswat.com/res...KeFc1ZGZGeE9HQkpaLTV1enR4X00/regular/overview
http://nodistribute.com/result/CdjULQGnTFlRz8V0DBEhwmSHM7ck
https://www.virustotal.com/#/file/3...e67af265047ec4dd0f3cb4b543b37cc9685/detection
 
Last edited by studio1b,
No real obvious detections in that, heurestics and generic detections could be false positives. But they could just as easily not.
Since it comes from devkitPro, it's most likely clean, but legit downloads have been hijacked to serve malware in the past, so you never know...
 
When I install the devkitpro updater version 2.0.0, or i update a previous updater to 2.0.0, windows defender tells me I have Trojan.Win32:Occamy.B I've installed this updater version on other windows PC's before without problem. What's going on?

My code signing certificate expired and I had to release an unsigned binary for the recent updates. Sadly this apparently means AV programs get over zealous and try to panic people. It's a false positive caused by heuristic analysis.

My devkitpro installer is still 1.6.0, and the official repo has the latest version being 1.7.0, so I'm unsure how you have 2.0.0

1.6.0 should be downloading 2.0.0. The official repo is on github @ https://github.com/devkitPro/installer/releases/tag/v2.0.0

Currently Sourceforge is in meltdown or I'd update what I can to inform people.

I did run a donation drive to raise funds for code cert renewal but, thanks to Myria I've now ordered the needed certificate and crypto card suite. Hopefully that will sort things out when I can sign the binary again.
 
My code signing certificate expired and I had to release an unsigned binary for the recent updates. Sadly this apparently means AV programs get over zealous and try to panic people. It's a false positive caused by heuristic analysis.



1.6.0 should be downloading 2.0.0. The official repo is on github @ https://github.com/devkitPro/installer/releases/tag/v2.0.0

Currently Sourceforge is in meltdown or I'd update what I can to inform people.

I did run a donation drive to raise funds for code cert renewal but, thanks to Myria I've now ordered the needed certificate and crypto card suite. Hopefully that will sort things out when I can sign the binary again.
Ok, thanks for the information!
 
Last edited by ballcity,
Please people, stop using online scanners like VirusTotal. They give nothing but a horribly mediocre glance at heuristics. Crypted malware especially will never be detected by them. Please use something like VxStream, which gives an in-depth analysis of the scanned binary. You'll get everything from network activity and pcaps, to registry and file system modifications. Ideally though, a Cuckoo virtual machine would be better, but I don't see many setting that up.
 
Last edited by Joom,

Site & Scene News

Popular threads in this forum