mirror of
https://github.com/netbootxyz/netboot.xyz.git
synced 2026-04-25 23:25:54 +03:00
[GH-ISSUE #1162] netboot.xyz.iso triggers Windows Defender for [Trojan:Script/Wacatac.H!ml] #320
Labels
No labels
Hacktoberfest
Hacktoberfest
bootloader
bsd
bug
confirmed
documentation
duplicate
enhancement
enhancement
enhancement
eol
experimental-merged
freebsd
help wanted
invalid
investigate
ipxe
linux
live-os
memdisk
menu
no-issue-activity
no-issue-activity
pull-request
released
todo
upstream
windows
windows
work-in-progress
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/netboot.xyz#320
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @runbgp on GitHub (Oct 12, 2022).
Original GitHub issue: https://github.com/netbootxyz/netboot.xyz/issues/1162
https://boot.netboot.xyz/ipxe/netboot.xyz.iso
Downloading the above ISO triggers Windows Defender malware detection causing the download to be blocked and removed.
webfile: C:\Users\runbgp\Downloads\netboot.xyz.iso|https://boot.netboot.xyz/ipxe/netboot.xyz.iso|pid:1908,ProcessStart:133100606421088571@antonym commented on GitHub (Oct 12, 2022):
More than likely it’s a false positive as I’ve seen in the past. https://github.com/netbootxyz/netboot.xyz/issues/781 Make sure you have the latest Defender and post your info for the definition files here so we can track.
@runbgp commented on GitHub (Oct 12, 2022):
Agreed - certainly a false positive. I was able to isolate it to this specific security intelligence version shown in the screenshot below. After updating just now to 1.377.123.0 it's no longer detecting a false positive.

@antonym commented on GitHub (Oct 12, 2022):
Thanks for the update!
@voltagex commented on GitHub (Oct 6, 2023):
@voltagex commented on GitHub (Oct 6, 2023):
I have submitted this as a false positive to Microsoft
https://www.microsoft.com/en-us/wdsi/submission/4a5b8b98-b5ff-4d5d-8fc3-55b6c98c951b
@voltagex commented on GitHub (Oct 6, 2023):
Looks like it's only the 1.399.129.0 definitions that were flagging it. Comes up clean on VirusTotal too.
https://www.virustotal.com/gui/file/4fee0b1b97e601600c3ea97e0c9362ff15498720218373aa4ed6b98957c246a2/behavior