View Issue Details

IDProjectCategoryView StatusLast Update
0002824SkyChart1-Softwarepublic25-04-22 08:54
ReporterChristian Roßberg Assigned ToPatrick Chevalley  
PrioritynormalSeverityminorReproducibilityalways
Status resolvedResolutionno change required 
PlatformPCOSWindowsOS Version10 64bit
Product Version4.3 beta 
Summary0002824: Windows Security detects trojan Trojan:Script/Wacatac.B!ml in skychart-4.3-4988-windows-x64.zip.
DescriptionMy OS version is Windows 11 64 bit
I've downloaded skychart-4.3-4988-windows-x64.zip and Microsoft Security detects Trojan:Script/Wacatac.B!ml with "severe" rating.
This has not been the case for skychart-4.3-4983-windows-x64.zip.

Is this a known issue from the past?
Unfortunately, I get no information what file is detected as "malicious".
In case this is a false positive, worth to submit to https://www.microsoft.com/en-us/wdsi/filesubmission
TagsNo tags attached.

Activities

Christian Roßberg

25-04-21 19:01

reporter  

Patrick Chevalley

25-04-21 20:36

administrator   ~0009376

This is strange you get this with the zip, this is the first time I see this error, but this is very common with the .exe installer.
The most common cause is false positive in compressed data.
This is less frequent with stable version or old files because how the "reputation" system work.

I try in a win11 virtual machine but for me it work without problem, both zip and exe.
Maybe try to update the antivirus, this often solve the problem with the .exe
My version is KB226602 (version 1.427.365.0)
From information on this page https://www.microsoft.com/en-us/wdsi/defenderupdates this is the last version released today.

Patrick Chevalley

25-04-21 20:49

administrator   ~0009377

One more point, here is the md5 sum of the file, run directly on the server that build it. Can you compare with the file you download?
$ md5sum skychart-4.3-4988-windows-x64.zip
3bd37441956cb9d3e4af1553063ce9e7 skychart-4.3-4988-windows-x64.zip

Christian Roßberg

25-04-21 22:13

reporter   ~0009378

I had to download the file again (the other one got removed after detection).
This works without any threat alerts. I've unpacked the zip and scanned the folder. No threats found this time.
md5sum is 3BD37441956CB9D3E4AF1553063CE9E7

Operational log for windows defender (Event 2000) shows the signature got updated at 2025-04-21 19:28:00:

Microsoft Defender Antivirus security intelligence version updated.
     Current security intelligence Version: 1.427.365.0
     Previous security intelligence Version: 1.427.361.0
     Security intelligence Type: AntiVirus
     Update Type: Delta
     User: NT AUTHORITY\SYSTEM
     Current Engine Version: 1.1.25030.1
     Previous Engine Version: 1.1.25030.1

-> Seems as Microsofts update fixed that issue after I did run into it.
-> This issue can be closed. Thank you for your support!

Issue History

Date Modified Username Field Change
25-04-21 19:01 Christian Roßberg New Issue
25-04-21 19:01 Christian Roßberg File Added: Screenshot 2025-04-21 184637.png
25-04-21 20:36 Patrick Chevalley Note Added: 0009376
25-04-21 20:49 Patrick Chevalley Note Added: 0009377
25-04-21 22:13 Christian Roßberg Note Added: 0009378
25-04-22 08:54 Patrick Chevalley Assigned To => Patrick Chevalley
25-04-22 08:54 Patrick Chevalley Status new => resolved
25-04-22 08:54 Patrick Chevalley Resolution open => no change required