Windows Defender 11 25H2 flagging geargrafx.exe #178
Description
Activity
- locked and limited conversation to collaborators
on Sep 2, 2026 - unlocked this conversation
on Sep 2, 2026 Yes. It happens from time to time with Defender and my emulators and it is quite random.
I guess it is because of the HTTP code of the MCP server.
The "!ml" thing at the end of the threat name means that it was detected due to machine learning, which you can search on the Internet it's quite flacky.
In case you have doubts, the whole supply chain is public in this repo and everything is generated from sources. All the code of my emulators including the generation of the binary, which is automatically created in GitHub Actions, is public here for everyone to audit.
Just sent the file to Microsoft for inspection, so hopefully it stops flagging it, but as I'm releasing very often I'm sure it will be flagged again soon.
Thanks for information and context. I already knew the whole high incidence of new code and emulation code in general being flagged by MS SmartScreen and by any anti-malware/anti-virus but I wanted to report it nonetheless as a change. Not out of any actual alarm over the code being malicious. Again, thanks for clearing this up.
Reacted by Nacho Sanchez Gines
Windows Defender (11 25H2) is reporting 1.7.20's geargrafx.exe has "Trojan:Win32/Wacatac.C!ml" (https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=Trojan%3AWin32%2FWacatac.C!ml&threatid=2147749372) where 1.7.19 and 1.7.18 did not trigger this.