Trojan:Win32/Fuerboos.A!cl detected in Win32 Packer Binary

23 views
Skip to first unread message

Manoj Vasudevan

unread,
Feb 22, 2018, 7:52:38 PM2/22/18
to Packer
I recently downloaded  32 bit binary using the link https://releases.hashicorp.com/packer/1.2.0/packer_1.2.0_windows_386.zip?_ga=2.123459467.147161268.1519346784-1125995714.1519346784 on a windows 10 machine  and the virus threat detection on my machine flagged the exe saying that the File has a Trojan called Fuerboos.A!cl

Trojan:Win32/Fuerboos.A!cl

I was able to workaround this with a MacOS version. Is this a know issue with Win32 binary? 
Thanks,

Matthew Hooker

unread,
Feb 22, 2018, 10:07:38 PM2/22/18
to packe...@googlegroups.com
Thanks for the report, Manoj. I'm almost certain this is a false positive. There is a similar issue on github for terraform, with lots of information there that I think also applies to packer: https://github.com/hashicorp/terraform/issues/16539. I've also verified that the checksum of the file you linked matches the contents of the signed shasum file.

I will try to reproduce and submit it for malware analysis to Windows Defender Security Intelligence. I will report back if it finds anything.

Thanks,
--Matt Hooker

--
This mailing list is governed under the HashiCorp Community Guidelines - https://www.hashicorp.com/community-guidelines.html. Behavior in violation of those guidelines may result in your removal from this mailing list.
 
GitHub Issues: https://github.com/mitchellh/packer/issues
IRC: #packer-tool on Freenode
---
You received this message because you are subscribed to the Google Groups "Packer" group.
To unsubscribe from this group and stop receiving emails from it, send an email to packer-tool...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/packer-tool/2c74d11f-ce8b-4435-a104-de731df6d179%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages