RE: ODBC MSI flagged as 'suspicious'
От | Rice, Daniel |
---|---|
Тема | RE: ODBC MSI flagged as 'suspicious' |
Дата | |
Msg-id | GV2PR08MB8027FD794219A3B3F8AAEF85FA232@GV2PR08MB8027.eurprd08.prod.outlook.com обсуждение исходный текст |
Ответ на | RE: ODBC MSI flagged as 'suspicious' ("Rice, Daniel" <Daniel.Rice@fisglobal.com>) |
Ответы |
Re: ODBC MSI flagged as 'suspicious'
|
Список | pgsql-odbc |
Hi again,
I’m told I have until Thurs to obtain a confirmation from PostgreSQL that the detections in the attached and following reports can be safely ignored.
Otherwise my company closes my ticket and I will not be allowed to use the PostgreSQL ODBC driver ☹.
Attached the analysis from CrowdStrike.
Link to Hybrid analysis: Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'psqlodbc_x64.msi' (hybrid-analysis.com)
Any help very much appreciated, thx.
Dan.
FIS Global.
From: Rice, Daniel
Sent: Thursday, February 29, 2024 2:27 PM
To: pgsql-odbc@postgresql.org
Subject: RE: ODBC MSI flagged as 'suspicious'
Hi all,
Is it possible to confirm detections in those reports can be safely ignored?
pgsql-security explained this is more of a packaging matter – please let me know if I should address to a different group.
Many thanks in advance,
Dan.
From: Rice, Daniel
Sent: Tuesday, February 27, 2024 9:57 AM
To: pgsql-odbc@postgresql.org
Subject: FW: ODBC MSI flagged as 'suspicious'
Hi all,
I want to use the PostgeSQL ODBC driver from psqlodbc - PostgreSQL ODBC driver, but my organisations security team explain to me the msi package (specifically psqlodbc_16_00_0000-x64.zip) is problematic for them as its not signed by Trusted CA and its flagged as Suspicious during sandbox analysis by Falcon & Hybrid Analysis.
They ask if the detections in those reports be safely ignored?
Attached the analysis from CrowdStrike.
Link to Hybrid analysis: Free Automated Malware Analysis Service - powered by Falcon Sandbox - Viewing online file analysis results for 'psqlodbc_x64.msi' (hybrid-analysis.com)
Many thanks in advance,
Daniel Rice
Exchange Project Management Lead - London, Americas
Documentation Product Owner
Valdi Global Markets
T: +44 20 8081 3670
M: +44 7802 490 388
FIS | Empowering the Financial World
CONFIDENTIALITY: This e-mail (including any attachments) may contain confidential, proprietary and privileged information, and unauthorized disclosure or use is prohibited. If you receive this e-mail in error, please notify the sender and delete this e-mail from your system.
P Think before you print
Вложения
- image001.png
- image002.png
- image003.png
- image004.jpg
- psqlodbc_x64.msi _ Sandbox _ Counter Adversary Operations _ Dynamic Analysis.pdf
- psqlodbc_x64.msi _ Sandbox _ Counter Adversary Operations _ Intelligence.pdf
- psqlodbc_x64.msi _ Sandbox _ Counter Adversary Operations _Mitre Attack.pdf
- psqlodbc_x64.msi _ Sandbox _ Counter Adversary Operations _ Static Analysis.pdf
В списке pgsql-odbc по дате отправления: