PHP-Antimalware-Scanner icon indicating copy to clipboard operation
PHP-Antimalware-Scanner copied to clipboard

detecting 15 infection in AWS SDK

Open rajeevkk32 opened this issue 4 years ago • 1 comments

HI, It is detecting 15 infections including TROJAN , ROOTKIT & BACKDOOR. Please help me in this. I am confused. composer require aws/aws-sdk-php https://docs.aws.amazon.com/sdk-for-php/v3/developer-guide/getting-started_installation.html

rajeevkk32 avatar Jul 30 '21 12:07 rajeevkk32

Hi, this antimalware detects some unconventional code patterns often used on malware to obfuscate code or do malicious operations, but not all of these are real malware but they could be false positives, and this usally happen on complex library like aws sdk.

So the way is to download the library again or detect if it is real malware or not is to check the line of code found and figure out if it is doing something dangerous or is it just a "bad practice" or a code pattern "not conventional".

Usually using the --only-signatures flag should be more secure and detect fewer false positives.

marcocesarato avatar Jul 31 '21 10:07 marcocesarato