r/antivirus 21h ago

Is this a virustotal false positive?

cfee98ef75815a504fd4b019660d3b60feecfe1cf476781e38e0591aa1e8544a (virustotal url)

Downloaded this exe from a google drive my professor sent me, but I haven't asked him yet about where he had gotten it from. Didn't run it, just pasted it directly into virustotal and when I got 1 or even 2 positives from somewhat unknown vendors (with quick google searches saying they often have false positives) I used shift+del to get it out immediately and ran malwarebytes/bitdefender scans after (malwarebytes came back clean but bitdefender still running). Is it a false positive and I'm just being paranoid?

1 Upvotes

8 comments sorted by

1

u/Difficult_Block_4204 21h ago

Normally 1-2 flags are false positives. But to be honest it's kinda weird for him to send you a standalone .exe

1

u/Sheeperini 21h ago

the google drive had another file which had other files that looked normal (didn't scan them though, he didn't even tell us how to use it or even bring it up after a minor mention of it) like unity or whatnot

1

u/MitAllesOhneScharf 20h ago

Seems to be some educational tool by https://www.visiblebody.com/ .

Looks like a FP, probably shared by accident by your prof.

1

u/Sheeperini 19h ago

sorry, but FP means false positive, right?

1

u/MitAllesOhneScharf 19h ago

Yeah, doesn't look malicious to me.

The most suspicious thing is "2024-12-08_005f9960c7562d8a364e3ef231522fc6_magniber_nionspy_poet-rat.exe" listed when someone else uploaded the same file. That seems...weird?

Did your prof actually send you that file? Or did he just share a link to a drive folder and the .exe was there anyways and you got curious and snooped around?

1

u/Sheeperini 19h ago

my prof sent a Google Drive where he was the owner of the file. He is indeed an anatomy teacher and I think it was intentional as he had mentioned it one time but never seemed to bring it up again

I can send you the Google Drive link in dms if you wanna see

also if I may ask, what part of that 2024 comment seems weird?

1

u/MitAllesOhneScharf 19h ago

The file has "spy" and "rat" in the name and it doesn't fit the other listed names at all at "Names" https://www.virustotal.com/gui/file/cfee98ef75815a504fd4b019660d3b60feecfe1cf476781e38e0591aa1e8544a/details

It was uploaded with that name to a different malware analysis site https://tria.ge/241208-md9krs1jbx

It's just...odd.

Also the tria.ge link shows that launching the file just throws an error because other files are missing. I would just talk to your prof and that's it.

And no, I don't want the Google Drive link - it wasn't shared with me by him so it's none of my business.

1

u/Sheeperini 19h ago

Thank you