Issue : https://www.virustotal.com/gui/file/e7d8904ceebbdae506485e64d341d80a998908011060ed58d188f62b989c70c7/behavior this sigma rule was deceted on this file : Syncfusion.Pdf.Imaging.NET.dll Crowdsourced Sigma Rules
CRITICAL 1
HIGH 0
MEDIUM 0
LOW 0
Matches rule Execute DLL with spoofed extension by Joe Security at Joe Security Rule Set (GitHub)
Execute DLL with spoofed extensionThe detection appears to be triggered by filename heuristics (e.g., usage of “pdf”) and partial DLL loading within sandbox environments, which mimics execution and activates rules such as "Execute DLL with spoofed extension." We've tested competitor DLLs (e.g., Aspose) under the same conditions and observed identical detections, confirming this is a false positive caused by sandbox behavior rather than any malicious activity. please remove this false positive alert.
It was detected in the behaviour analysis category by the ZEN Sandbox.
Note : The detection appears to be triggered by filename heuristics (e.g., usage of “pdf”) and partial DLL loading within sandbox environments, which mimics execution and activates rules such as "Execute DLL with spoofed extension." this rule is specific to pdf related assemblies only.
We've tested competitor DLLs (e.g., Aspose, pdfpig ) under the same conditions and observed identical detections, confirming this is a false positive caused by sandbox behavior rather than any malicious activity.
No malicious behavior (e.g., dropped files, network activity, or IDS alerts) was observed. The detection results from artificial sandbox conditions and filename heuristics, not real-world threats.
These DLLs are safe for use in production.
Looking forward to your response for the removal of this sigma rule detection for our dlls
Issue : https://www.virustotal.com/gui/file/e7d8904ceebbdae506485e64d341d80a998908011060ed58d188f62b989c70c7/behavior this sigma rule was deceted on this file : Syncfusion.Pdf.Imaging.NET.dll Crowdsourced Sigma Rules
CRITICAL 1
HIGH 0
MEDIUM 0
LOW 0
Matches rule Execute DLL with spoofed extension by Joe Security at Joe Security Rule Set (GitHub)
Execute DLL with spoofed extensionThe detection appears to be triggered by filename heuristics (e.g., usage of “pdf”) and partial DLL loading within sandbox environments, which mimics execution and activates rules such as "Execute DLL with spoofed extension." We've tested competitor DLLs (e.g., Aspose) under the same conditions and observed identical detections, confirming this is a false positive caused by sandbox behavior rather than any malicious activity. please remove this false positive alert.
It was detected in the behaviour analysis category by the ZEN Sandbox.
Note : The detection appears to be triggered by filename heuristics (e.g., usage of “pdf”) and partial DLL loading within sandbox environments, which mimics execution and activates rules such as "Execute DLL with spoofed extension." this rule is specific to pdf related assemblies only.
We've tested competitor DLLs (e.g., Aspose, pdfpig ) under the same conditions and observed identical detections, confirming this is a false positive caused by sandbox behavior rather than any malicious activity.
No malicious behavior (e.g., dropped files, network activity, or IDS alerts) was observed. The detection results from artificial sandbox conditions and filename heuristics, not real-world threats.
These DLLs are safe for use in production.
Looking forward to your response for the removal of this sigma rule detection for our dlls