this post was submitted on 09 Nov 2024
45 points (89.5% liked)

Humble Bundle

335 readers
1 users here now

Unofficial community for the Humble Bundle website!

Community logo taken from https://www.humblebundle.com/

founded 1 year ago
MODERATORS
 

I tried posting this on Reddit but the mods have to approve it and haven't yet. I'll warn you guys.

I just downloaded the HumbleBundle Programming MEGA Bundle 2024 by Packt via torrent and stored it in my NAS. That system ran a virus check and found the file pragmaticmicroserviceswithcandazure.zip had a virus Win.Packed.Pwsx-10034067-0 in it. Is this common on HumbleBundle? I would expect something like this on a cybersecurity bundle for studying viruses but not on one about microservices. This zip file is for the book Pragmatic Microservices with C# and Azure.

all 20 comments
sorted by: hot top controversial new old
[–] [email protected] 19 points 3 days ago (1 children)

There is a chance that it is setting off a false positive some kind of heuristic. But it is definitely worth looking into more. Is it setting off windows defender?

[–] Eezyville 3 points 3 days ago

It's not in Windows. The bundle was bought on their website and I used the torrent option to get the files through downloading them to my Linux server acting as a NAS. That server runs regular virus scans before I let it interact with any other system.

[–] [email protected] 7 points 3 days ago (1 children)

You said you are running linux so you are pretty safe from a windows virus. Judging by the book and the alert it likely saw some PowerShell code and got a bit concerned about PowerShell inside a pdf inside a zip, a known way to deliver malware.

I would do 2 things.

Contact humble support, it may have been reported and they can reassure you of the validity of the file. Secondly, Submit the file to virus total and see if anything else sees it as a known malware sample.

[–] Eezyville 4 points 3 days ago (1 children)

Hey thanks for the reply. I just discovered this virustotal website and submitted the file there. Here is the results from their scan. It looks like only ClamAV found the virus so it may be a false positive. I just got worried because I often buy books from HumbleBundle and this is the second time ClamAV quarantined a file from them.

[–] [email protected] 1 points 3 days ago

Might be worth tracking down one of the researchers submitting to the clamav software repos and forwarding them a copy of the flagged zip. If they don't dig in and find malware, they could at least improve the detection algo

[–] [email protected] 7 points 3 days ago (1 children)

Are you certain you were using an official download source?

[–] Eezyville 0 points 3 days ago (1 children)

I downloaded the torrents directly from their website after I paid for the books.

[–] [email protected] 3 points 3 days ago (1 children)

Could you provide some screenshots?

This is a bit hard to believe without seeing what you're seeing as I've personally never seen Humblebundle provide torrent links(maybe things have changed recently?)

[–] Eezyville 1 points 3 days ago (1 children)

Here's a screenshot: Screenshot Here's a link to virustotal: VirusTotal

[–] [email protected] 1 points 3 days ago

I did try to imply I wanted to see a screenshot of the download link from Humblebundle

[–] [email protected] 3 points 3 days ago* (last edited 3 days ago) (1 children)

Not normal, but I have seen 100x more false positives than real detections over the years. Proceed with caution, but as long as it isn't an EXE you're running and/or the author seems trustworthy, I wouldn't worry much.

[–] Eezyville 1 points 3 days ago

The virus detection program was ClamAV on my linux box. It does regular scans after I finish torrents.