elastic / elastic/protections-artifacts
False positive: EV-signed, VMProtect-packed app flagged as Malicious (high Confidence)
- Dominant language
- YARA
- Stars
- 1.5k
- Forks
- 169
- Avg merge
- 29m
- Merged PRs (30d)
- 2
Description
This is a false positive. RiseClient.exe is our own legitimately developed
commercial game client, published by Rise of Revolution Ltd and digitally
signed with our EV code-signing certificate (GlobalSign, "Rise of Revolution Ltd").
It is protected with VMProtect, a legitimate commercial software protector,
which is what triggers the "Malicious (high Confidence)" verdict. The file
contains no malicious code.
VirusTotal: https://www.virustotal.com/gui/file/6513eef22700a42018b71ef21dfd09328b708ecc8fbc21da39212bd658b64969
SHA-256: 6513eef22700a42018b71ef21dfd09328b708ecc8fbc21da39212bd658b64969
Please review and allowlist this file / our signing certificate.
Contributor guide
No contributing guide indexed for this repository
Research direction
No repository file, test, or entry point is named. Start by reviewing the VirusTotal report and SHA-256 for RiseClient.exe, then inspect how VMProtect and the stated EV certificate relate to the verdict. Done means the false-positive claim is resolved and the file or signing certificate is allowlisted if the review confirms it.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100