Re: BitDefender false positive on 2 files?

Arnaud Rebillout <[email protected]> Fri, 10 Apr 2026 14:29:57 +0700
Newsgroups gmane.linux.debian.user.mirrors
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------J20JzQPeu5rQ0D3LyW9Dg68O
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

```
$ apt show pocsuite3 python3-impacket | grep ^Description
Description: Open-sourced remote vulnerability testing framework
Description: Python3 module to easily build and dissect network protocols
```

pocsuite3 is an infosec tool, I suppose it contains bits of malware in 
its test files, or something like that. Maybe the same for impacket. So 
it's very likely to be false positive indeed.

You should try to confirm that by checking which files exactly are 
flagged as malware.

Best,

Arnaud


On 10/04/2026 13:52, OSLUZ wrote:
>
> I ran the two files through VirusTotal.com, and it flagged them as 
> malicious
>
> Regards
>
> ________________________________________
>   
> Oficina de Software Libre
> Servicio de Informática y Comunicaciones
> Universidad de Zaragoza
> https://osluz.unizar.es/
> ________________________________________
> El 10/4/26 a las 1:05, Santiago Roland escribió:
>> Hi, i just run Bit Defender full scan on the mirror server and it detected 2 files as malware.
>>
>> /pool/main/p/pocsuite3/pocsuite3_1.9.6.orig.tar.gz
>> Threat name: Trojan.GenericKD.79774915
>>
>>
>> /pool/main/i/impacket/impacket_0.12.0.orig.tar.gz
>> Threat name: Adware.GenericKD.61104868
>>
>> Could this be a false positive? Should i add an exclusion on these?
>>
>> Cheers
>>
--------------J20JzQPeu5rQ0D3LyW9Dg68O
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    ```<br>
    $ apt show pocsuite3 python3-impacket | grep ^Description<br>
    Description: Open-sourced remote vulnerability testing framework<br>
    Description: Python3 module to easily build and dissect network
    protocols<br>
    ```
    <p>pocsuite3 is an infosec tool, I suppose it contains bits of
      malware in its test files, or something like that. Maybe the same
      for impacket. So it's very likely to be false positive indeed.</p>
    <p>You should try to confirm that by checking which files exactly
      are flagged as malware.</p>
    <p>Best,</p>
    <p>Arnaud</p>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 10/04/2026 13:52, OSLUZ wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <p>I ran the two files through VirusTotal.com, and it flagged them
        as malicious</p>
      <p>Regards</p>
      <pre class="moz-signature" cols="72">________________________________________
 
Oficina de Software Libre
Servicio de Informática y Comunicaciones
Universidad de Zaragoza
<a class="moz-txt-link-freetext" href="https://osluz.unizar.es/"
      moz-do-not-send="true">https://osluz.unizar.es/</a>
________________________________________</pre>
      <div class="moz-cite-prefix">El 10/4/26 a las 1:05, Santiago
        Roland escribió:<br>
      </div>
      <blockquote type="cite"
        cite="mid:[email protected]">
        <pre wrap="" class="moz-quote-pre">Hi, i just run Bit Defender full scan on the mirror server and it detected 2 files as malware.

/pool/main/p/pocsuite3/pocsuite3_1.9.6.orig.tar.gz
Threat name: Trojan.GenericKD.79774915


/pool/main/i/impacket/impacket_0.12.0.orig.tar.gz
Threat name: Adware.GenericKD.61104868

Could this be a false positive? Should i add an exclusion on these?

Cheers

</pre>
      </blockquote>
      <lt-container></lt-container>
    </blockquote>
  </body>
</html>

--------------J20JzQPeu5rQ0D3LyW9Dg68O--