Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-17 Thread Lex Trotman
On Tue, 18 Dec 2018 at 11:23, Matthew Brush wrote: > > Hi, > > The installer doesn't connect to the Internet, your report shows Windows > connecting to the Internet (svchost.exe). Oh dear, Windows is a virus, quick remove it :) ___ Users mailing list Us

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-17 Thread Matthew Brush
Hi, The installer doesn't connect to the Internet, your report shows Windows connecting to the Internet (svchost.exe). As suggested, it's most likely Windows checking your Internet connection by connecting to a (somewhat) regional IP which will always be online (ex. a CDN). For more info, goo

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-17 Thread dany111
So, if I run the installer offline, I should be safe, right? Because the suspicious behavior is restricted to internet connection and to the installation, when installer acts, and never again. Regards, Daniel - Original Message - Hi, I don't think your conclusion is correct: in my opi

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-17 Thread Enrico Tröger
Hi, I don't think your conclusion is correct: in my opinion it is not yet proven that the installer actually connects to the internet yet it is possible (I could not reproduce it on my system but this does not necessarily mean it does not happen). And if it connects to the internet, then it is no

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-17 Thread dany111
Thanks for the answer. So, the installer connects to internet, not Geany itself, right? In conclusion, the installer is safe, isn't it? PS:Could I ask you which tools you use to monitor network activity and to grep whole Windows system? - Original Message - On 12/16/18 11:29 PM, Enrico

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-16 Thread Matthew Brush
Hi, I got a Windows Defender warning with the just-released installer, similar to Issue #990[0]. In order to install you have to run as administrator and then allow it. I expect it's because it's a random .exe from the internet with lots of compressed, executable code, which makes system-wid

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-16 Thread Enrico Tröger
On 12/16/18 11:29 PM, Enrico Tröger wrote: > Hi, > > On 12/16/18 10:37 PM, dany...@email.it wrote: >> I don't want to sound paranoid but I've just scanned geany binaries with >> Hybrid Anlisys. >> I've got these results: >> https://www.hybrid-analysis.com/sample/109748fc6e6276462258ee104996fe29c

Re: [Geany-Users] geany-1.34_setup.exe security analysis

2018-12-16 Thread Enrico Tröger
Hi, On 12/16/18 10:37 PM, dany...@email.it wrote: > I don't want to sound paranoid but I've just scanned geany binaries with > Hybrid Anlisys. > I've got these results: > https://www.hybrid-analysis.com/sample/109748fc6e6276462258ee104996fe29c9d826b4ea507857e7a2411b1614bd7d/5c1698807ca3e12dc155b

[Geany-Users] geany-1.34_setup.exe security analysis

2018-12-16 Thread dany111
I don't want to sound paranoid but I've just scanned geany binaries with Hybrid Anlisys. I've got these results: https://www.hybrid-analysis.com/sample/109748fc6e6276462258ee104996fe29c9d826b4ea507857e7a2411b1614bd7d/5c1698807ca3e12dc155b5ad In particular, could you explain me why the installer c