@rdipardo said in Compare plugin detected as malicious by both JoeSandbox and Crowdstrike Falcon:
…it unpacks portable versins of sqlite3 and git2, which it needs to function; but these are flagged as potentially malicious “stowaways”:
Persistence and Installation Behavior
Drops PE files
Source: C:\Windows\SysWOW64\7za.exe
File created: C:\Users\user\Desktop\extract\ComparePlugin\sqlite3.dllSource: C:\Windows\SysWOW64\7za.exe
File created: C:\Users\user\Desktop\extract\ComparePlugin\git2.dllSource: C:\Windows\SysWOW64\7za.exe
File created: C:\Users\user\Desktop\extract\ComparePlugin.dll
Yes. It appears the sqlite3.dll and git2.dll files are the ones actually causing the Hybrid-Analysis sandbox to register the whole .zip as malicious as well. Not sure the best way to test them to verify they are good…