Post

Auto Submit False-Positive/Negative Files

Introduction

Malware researchers often encounter some AV vendors fail to detect a malware sample, or falsely flags a normal file as being malicious. To build an automatic process of reporting the FP/FN files, I wrote a python tool for compressing samples and submitting to AV vendors via email.

Features

  • Automatically compress all files into a single encrypted zip.
  • Customizable Zip password and Email content.
  • Add/Remove items from Antivirus vendor list
  • Automatically save login info
  • Send with one click
  • Multi-language support (English or Chinese Simplified)

Screenshot

Desktop View

View Project

List of AV Vendors and Emails

AV VendorFalse-NegativeFalse-Positive
Kasperskynewvirus@kaspersky.com-
ESETsamples@eset.comsamples@eset.com
Mcafeevirus_research@mcafee.comvirus_research@mcafee.com
Bitdefendervirus_submission@bitdefender.comvirus_submission@bitdefender.com
Aviravirus@avira.comnovirus@avira.com
Emsisoftsubmit@emsisoft.comfp@emsisoft.com
Sophossamples@sophos.comsamples@sophos.com
This post is licensed under CC BY 4.0 by the author.