elastic / elastic/protections-artifacts

False positive: EV-signed, VMProtect-packed app flagged as Malicious (high Confidence)

Open
#129 1 comment 0 reactions 0 assignees View on GitHub
behavior custom
Dominant language
YARA
Stars
1.5k
Forks
169
Avg merge
29m
Merged PRs (30d)
2

Description

This is a false positive. RiseClient.exe is our own legitimately developed
commercial game client, published by Rise of Revolution Ltd and digitally
signed with our EV code-signing certificate (GlobalSign, "Rise of Revolution Ltd").
It is protected with VMProtect, a legitimate commercial software protector,
which is what triggers the "Malicious (high Confidence)" verdict. The file
contains no malicious code.

VirusTotal: https://www.virustotal.com/gui/file/6513eef22700a42018b71ef21dfd09328b708ecc8fbc21da39212bd658b64969
SHA-256: 6513eef22700a42018b71ef21dfd09328b708ecc8fbc21da39212bd658b64969

Please review and allowlist this file / our signing certificate.

Contributor guide

No contributing guide indexed for this repository

Research direction

No repository file, test, or entry point is named. Start by reviewing the VirusTotal report and SHA-256 for RiseClient.exe, then inspect how VMProtect and the stated EV certificate relate to the verdict. Done means the false-positive claim is resolved and the file or signing certificate is allowlisted if the review confirms it.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.