-
Notifications
You must be signed in to change notification settings - Fork 207
Open
Labels
false positiveFalse positive rule hitFalse positive rule hit
Description
file: https://www.virustotal.com/gui/file/18fccc911770c26135feb4837cc40920c798c57bc062cbdfb29641a891720938
| Function Address | Capability | Verdict (TP/FP) | Evidence & Reasoning | Suggested Fix |
|---|---|---|---|---|
| 0x4064C3 | create UDP socket | ❌ FP | The code calls socket(2, 1, 6). Protocol 6 is IPPROTO_TCP, not UDP. |
Check the protocol argument in socket calls; ensure it is 17 (UDP) or 0 (with SOCK_DGRAM). |
Metadata
Metadata
Assignees
Labels
false positiveFalse positive rule hitFalse positive rule hit