Trojan False Positive on CMS software (Sofia/34567/Top-210 cameras)

cybermaus

Young grasshopper
Joined
May 26, 2016
Messages
57
Reaction score
13
FYI

Yesterday MalwareBytes MBAM suddenly pointed to my CMS camera management software as a Trojan. Specifically file HW_H265Decoder.DLL was seen as Throjan.Tracur

Not having done any updates in a while, and this folder not being a typical target for dynamic infection, I suspected (hoped for) a false positive and reported to Malwarebytes.

Just now they confirmed it was a false positive, and they will fix it.
So if you have the same, don't worry.
 

nayr

IPCT Contributor
Joined
Jul 16, 2014
Messages
9,329
Reaction score
5,325
Location
Denver, CO
its not a false positive; the malware is present on the cameras firmware.. this has been well documented.

you should be worrying.
 

cybermaus

Young grasshopper
Joined
May 26, 2016
Messages
57
Reaction score
13
Yeah, so what you are saying is that because it is know that some IoT firmware do have known malware in their firmware, a message of my PC software must be true. Even if professional experts have double checked and confirmed this specific file good?

You are either a fear-mongerer, or very badly understand how software works.


Anyway, to restate: I am not saying there are no virusses or trojans anyware on camera's. They do exist.
I am saying that the specific recent MalwareByte report on windows32 PC file HW_H265Decoder.DLL is false. Confirmed by MalwareByte support themselves after uploading and inspecting the file.
 

nayr

IPCT Contributor
Joined
Jul 16, 2014
Messages
9,329
Reaction score
5,325
Location
Denver, CO
no what im saying is I have that same camera sitting in my junk bin and it came loaded with real malware that was loaded externally from a hidden iframe.. it didnt have actual malware on it but it did try to load an external page to infect me in the background.. it was not a false positive.

weather or not this malware is real; this specific camera has a history of shipping w/malware infected firmware.. so just dismissing it as a false positive is unwise on many levels.
 

hmjgriffon

Known around here
Joined
Mar 30, 2014
Messages
3,386
Reaction score
979
Location
North Florida
If it's running Chinese firmware the malware is built in complete with back doors lol.

Sent from my Nexus 6P using Tapatalk
 

cybermaus

Young grasshopper
Joined
May 26, 2016
Messages
57
Reaction score
13

alastairstevenson

Staff member
Joined
Oct 28, 2014
Messages
15,952
Reaction score
6,787
Location
Scotland
Well that's a clear enough result, nails it. Especially as they now have Malwarebytes in the pool.
 
Top