Hacker News new | ask | show | jobs
by mizaru 1544 days ago
Blackbird gets blocked by Defender immediately. Not sure why I'm surprised.

edit: Then again, that tool does seem to make it quite easy to damage your Windows installation.

1 comments

I don't trust it because it is a closed source binary and there is a lack of detailed documentation of exactly what settings it changes.
You could run it in a VM and see what changes are made. Given that Jotti by and large says it is benign (very few positive results), it's probably okay. Such trojan flagging as you see here is frequently a result of binary compression or packing.