Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[email protected]: hash check failed #6323

Closed
skyoh-nsuslab opened this issue Nov 13, 2024 · 1 comment
Closed

[email protected]: hash check failed #6323

skyoh-nsuslab opened this issue Nov 13, 2024 · 1 comment

Comments

@skyoh-nsuslab
Copy link

ERROR Hash check failed!
App: main/ngrok
URL: https://bin.equinox.io/a/4vvyKGoo1gc/ngrok-v3-3.18.4-windows-amd64.zip
Expected: 0ec8cf167a77ae420d7f483e74ac6bad6e653c36cccb03ddd8c9fd9f8b49ff24
Actual:

During the installation of ngrok 3.18.4, Microsoft Defender flagged the ngrok file from the provided URL as Trojan
/Sabsik.FL.A!ml (Trojan:Script/Wacatac.H!ml) and subsequently quarantined it. Upon scanning the zip file on VirusTotal, some antivirus engines identified it as malware. According to descriptions, this could potentially be due to a "fat finger" issue.

zip file
https://www.virustotal.com/gui/file/0ec8cf167a77ae420d7f483e74ac6bad6e653c36cccb03ddd8c9fd9f8b49ff24

exe file (zip extract)
https://www.virustotal.com/gui/file/a0f02163062dc25ce4a8256570427fc761855a3189b0650986eedc1f2770f552

The scan matched the rule “Cmd.EXE Missing Space Characters Execution Anomaly” by Florian Roth (Nextron Systems) on the Sigma Integrated Rule Set (GitHub). This rule detects Windows command lines that omit a space before or after the /c flag when running a command with cmd.exe. Such behavior may indicate an attempt at obfuscation or simply be the result of a developer typo.

based on my long-term experience using ngrok through Scoop, security warnings sometimes occur during ngrok updates via Scoop, which has gradually led me to lose trust in using ngrok. 😭

Copy link
Contributor

Cannot reproduce

Are you sure your scoop is up to date? Clean cache and reinstall
Please run scoop update; scoop cache rm ngrok; and update/reinstall application

Hash mismatch could be caused by these factors:

  • Network error
  • Antivirus configuration
  • Blocked site (Great Firewall of China, Corporate restrictions, ...)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant