The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CO2 extension marked by antiviruses as malware

Martin | Last updated: Nov 03, 2023 06:28PM UTC

The CO2 extension is considered malware by more AV/EDR vendors. I could not find a reason behind it and our EDR vendor did not share their reasons either. Do you have a clue what is going on here? The page for the extension is https://portswigger.net/bappstore/c5071c7a7e004f72ae485e8a72911afc. The source code is at https://github.com/portswigger/co2 (I did not compile it myself to verify). The bundled file is marked as malware by many vendors: https://www.virustotal.com/gui/file/1ab1e466597ecff0602829b7a1c8f88aa1a56a0a0040c0df6e54d18366b4d2f5 (I suspect that because it is a penetration testing tool, some strings might be a trigger for detection, but it's not clear anyway, because the extension bundles a few other tools and almost none of them contains such strings (except sqlmap). The behavior should not be suspicious, except that it modifies the system when installing the other tools.)

Hannah, PortSwigger Agent | Last updated: Nov 06, 2023 10:19AM UTC