evercookie icon indicating copy to clipboard operation
evercookie copied to clipboard

Malware detected

Open AceGambit opened this issue 12 years ago • 14 comments

Just to let you know Symantec Endpoint Protection has just detected malware in the evercookie-master.zip download "Trojan.Maljava!gen26" in evercookie.jar

AceGambit avatar Nov 11 '13 14:11 AceGambit

Hahaha, true. Eset found it too.

dretax avatar Jul 15 '14 09:07 dretax

Hah, interesting, does that quarantine evercookie entirely? Perhaps I can have it be downloaded separately if it is removing the entire zip/package if that's the case.

samyk avatar Jul 15 '14 16:07 samyk

Hmm, looks like the exploit I used to try to break out of the Java sandbox is being detected. I can build a version without it if you like, or I can do some obfuscation to prevent detection. On my test systems the rest of evercookie works fine, but we can't have people getting virus warnings when visiting evercookie sites.

gabrielbauman avatar Jul 15 '14 16:07 gabrielbauman

An obfuscated version that evades the filters would be awesome. If we find that it's rediscovered in the future, we can have two separate versions and have users perform an additional step to acquire the drop-it-like-it's-hot-java version.

samyk avatar Jul 15 '14 16:07 samyk

Okay, I will see what I can pull together. It might take me a few days - things are extremely busy at work right now.

gabrielbauman avatar Jul 16 '14 07:07 gabrielbauman

No worries, appreciate you looking into this!

samyk avatar Jul 16 '14 07:07 samyk

Okay, I spent some time on this. Current detection status: http://virusscan.jotti.org/en/scanresult/a574f7b18262d0b0b3566eb3cefe1d026c961d62. Four scanners to go until we hit stealth mode again ;)

gabrielbauman avatar Jul 16 '14 08:07 gabrielbauman

Oh man, this is rad

samyk avatar Jul 16 '14 18:07 samyk

This is still happening with Windows Defender. Tried to install evercookie through Bower and it was throwing errors. Windows Defender showed it was detected as malware. Once I allowed it through Windows Defender, all was well. Works great through Bower on my Mac's.

Speaking of -- it would be awesome if this was listed in the Bower package directory.

http://bower.io/search/

mikeytusa avatar Aug 28 '14 03:08 mikeytusa

I've got virus warning in Kaspersky anti-virus - virus found in evercookie.jar. Will the rest of it work, if I just delete evercookie.jar?

AlinaSob avatar Dec 15 '14 13:12 AlinaSob

@gabrielbauman You'll also want to check it against VirusTotal.

The page you linked only lists 22 scanners while VirusTotal has 54.

ssokolow avatar Dec 15 '14 14:12 ssokolow

so ... how to download?

stratocentric avatar May 10 '16 01:05 stratocentric

Will evercookie work without the evercookie.jar file?

chrislandeza avatar Oct 05 '17 09:10 chrislandeza

Yes, removing the jar only disables the Java based mechanism.

samyk avatar Oct 05 '17 19:10 samyk