Author Topic: ===> False Positives <===  (Read 351402 times)

0 Members and 1 Guest are viewing this topic.

Reply #390October 29, 2019, 07:39:11 PM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #390 on: October 29, 2019, 07:39:11 PM »
Hi

Can you check this please see my screenshot

With best Regards
Mops21

Reply #391October 29, 2019, 10:17:37 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #391 on: October 29, 2019, 10:17:37 PM »
Hi Mops21,

This look like false positives.
Could you please make an archive containing these files and attach it with your next reply ?

Regards.

Reply #392October 30, 2019, 11:36:01 AM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #392 on: October 30, 2019, 11:36:01 AM »
Hi

Yes here are the Files but the first second Files can I not find on my System where the Folder exist no

https://www.sendspace.com/file/8ztbws

With best Regards
Mops21

Reply #393October 30, 2019, 06:45:25 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #393 on: October 30, 2019, 06:45:25 PM »
Hi Mops21,

Thank your very much.
The archive contains the most important files, so it's alright.

Regards.

Reply #394October 30, 2019, 07:43:08 PM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #394 on: October 30, 2019, 07:43:08 PM »
Hi

Also need you the other 2 Files anymore right or need you the 2 Files

With best Regards
Mops21

Reply #395October 30, 2019, 07:53:26 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #395 on: October 30, 2019, 07:53:26 PM »
Hi Mops21,

No, the archive contained all the files we need.
However, it may take time until this is fixed. Please ignore these detections for the time being.

Regards.

Reply #396October 31, 2019, 11:24:58 AM

Mops21

  • Jr. Member

  • Offline
  • **

  • 64
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #396 on: October 31, 2019, 11:24:58 AM »
Hi

Okay thank you very much for your Infos

With best Regards
Mops21

Reply #397October 31, 2019, 11:21:45 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #397 on: October 31, 2019, 11:21:45 PM »
Hi Mops21,

You are very welcome.
Thanks again for your feedback.

Regards.

Reply #398November 14, 2019, 04:14:41 PM

techknowledge

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #398 on: November 14, 2019, 04:14:41 PM »
The powershell script that calls rogue killer via my MSP gets killed by rogue killer. As a result code after the portion that runs roguekiller does not run.
The powershell script in the log will change with each run.

Thank you for your time.

Scan log file:
Code: [Select]
RogueKillerCMD V2.5.3.0 (x64) [Nov  8 2019] (Premium) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekillercmd/
Operating System : Windows 10 (10.0.17763) 64 bits
Started in : Normal mode
User : SYSTEM [Admin rights]
Started from : C:\Programdata\TechKnowledgeCleanup\bin\scanners\roguekiller\roguekillercmd.exe
[[SIGNATURES]] : 20191112_105343, [[DRIVER]] : LOADED
Mode : Standard Scan, Remove -- Date : 2019/11/12 11:42:02 (Duration : 00:03:54)
Switches : -reportformat txt -reportpath C:\Programdata\TechKnowledgeCleanup\logs\RogueKillerLog.txt -portable-license C:\Programdata\TechKnowledgeCleanup\bin\scanners\roguekiller\rk.lic

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Remove ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[Mal.Powershell ([[MALICIOUS]])] powershell.exe -- %ProgramFiles%\Pulseway\automation_c15ddc4a_4ca5_4033_9985_ae772f03c0cc.ps1 -> ERROR [0]

Reply #399November 15, 2019, 01:50:08 AM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #399 on: November 15, 2019, 01:50:08 AM »
Hi techknowledge,

Thanks for your feedback.
Could you please zip the detected powershell script and attach it with your next reply ?

Regards.

Reply #400November 15, 2019, 03:23:43 PM

techknowledge

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #400 on: November 15, 2019, 03:23:43 PM »
Unfortunately I will not be able to provide the script. However the script itself is not important in this situation. There are many scripts that I run through my MSP. They all run from that folder.

I fully understand not being able to white list a folder.
I was thinking more along the lines of providing a whitelist command line argument. If n argument already exists, could I get documentation on how to use it?

As it stands I have been forced to omit RougueKiller from my cleanup process.

Thank you again for your time, I do appreciate it.

Reply #401November 15, 2019, 09:07:45 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: ===> False Positives <===
« Reply #401 on: November 15, 2019, 09:07:45 PM »
Hi techknowledge,

There does not exist such a switch at the moment.
Maybe, you could share the script with sensitive information removed ? Which parameters are passed to Powershell binary along the script ?


Regards.

Reply #402November 18, 2019, 03:43:02 PM

techknowledge

  • Newbie

  • Offline
  • *

  • 5
  • Reputation:
    0
    • View Profile
Re: ===> False Positives <===
« Reply #402 on: November 18, 2019, 03:43:02 PM »
I understand now.
$args = @"
-scan "-reportformat txt -reportpath $ThisApplicationLogFile -portable-license $roguekillerlicense" -autodelete -no_interact
"@
Start-Process -FilePath $roguekillerexe -ArgumentList $args -Wait -RedirectStandardError $stdErrLog -NoNewWindow

Would it be change out -autodelete with something? I get the log sent every time it runs. If there is anything found in the log it goes direct to a tech rather than the general logging email address.

Could we create a follow up script that uses the log file to delete things previous found? That way we would avoid a second scan.

Reply #403November 29, 2019, 04:26:55 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: ===> False Positives <===
« Reply #403 on: November 29, 2019, 04:26:55 PM »
Hey, sorry for the delay.
I'll be looking into it very shortly.

Reply #404November 29, 2019, 05:32:27 PM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 956
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: ===> False Positives <===
« Reply #404 on: November 29, 2019, 05:32:27 PM »
So indeed yes we detect when a powershell script is beeing executed.
However since it's a process only it won't be deleted, just stopped.

The easy fix for us would be to whitelist the file with a pattern, is that ok ?
Can you tell me what rule you file name follows ?

Regards,