False Positive - WhatsMinerTool 9.2.5 flagged as Trojan

Q 大 0 Reputation points
2026-08-25T08:31:56.68+00:00

Hello Microsoft Security Response Center,

I am reporting a false positive that affects our legitimate production software. The WDSI submission portal returns an error when I try to submit, so I am escalating through MSRC.

--- File Information --- Software name: WhatsMinerTool 9.2.5 Software purpose: Official management tool for WhatsMiner (Bitmain brand) cryptocurrency mining rigs. Used to configure, monitor, and upgrade mining hardware via IP. It is a management client, NOT a miner itself. File name: WhatsMinerTool-9.2.5.zip (contains WhatsMinerTool-customer.exe) File size: 3.18 MB (3,333,438 bytes) SHA-256: 2899C262649A5408E1B421BC9F1C303245A526A1486743C8EA23DECD56F123EE

--- Detection Information --- Detection name 1: Trojan:Win32/Suschillrfn Detection name 2: Trojan:Win32/Wacatac.B!ml (cloud heuristic) Detection path: D:\bill\工具\工具测试报告\WhatsMinerTool-9.2.5测试报告
WhatsMinerTool-9.2.5\WhatsMinerTool-9.2.5\WhatsMinerTool-customer.exe

--- Issue with WDSI Portal --- I attempted to submit this false positive via the WDSI portal (https://www.microsoft.com/wdsi/filesubmission) using a personal outlook.com account, but the portal returns an error every time: "An error has occurred. If you don't see your submitted file on the submission history page, please try again." No submission appears in the history page. This appears to be a known portal bug (confirmed in Microsoft Tech Community posts).

--- Request --- Please re-analyze the attached file and remove the false positive detections. This is an official, legitimate management tool and the detections are incorrect.

Contact email: ******@microbt.com

【Attachment / 附件】 Upload: WhatsMinerTool-9.2.5.zip Path: D:\bill\工具\工具测试报告\WhatsMinerTool-9.2.5测试报告\WhatsMinerTool-9.2.5\WhatsMinerTool-9.2.5.zip

【Contact Email / 联系邮箱】 ******@microbt.com

Microsoft Security | Microsoft Defender | Other

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-25T08:32:16.69+00:00

    Use the supported false-positive submission paths instead of MSRC escalation.

    1. Submit the file in the Microsoft Defender portal:
      • Go to Microsoft Defender portal > Investigation & response > Actions & submissions > Submissions.
      • Open the Files tab.
      • Select Add new submission.
      • Choose Files.
      • Upload the file.
      • Set The file should have been categorized as to Clean (false positive).
      • Set priority as needed: Low, Medium, or High - needs immediate attention.
      • Add notes describing the detection names and that the file is legitimate.
      • Select Submit.
    2. If the file cannot be uploaded, submit the file hash instead:
      • In the same Submissions page, choose File hash.
      • Enter the SHA-256 value.
      • Set The file should have been categorized as to Clean (false positive).
      • Add notes and submit.
    3. If the Defender portal path is not available, use the Microsoft Security Intelligence submission site to submit the file for malware analysis.
    4. After submission, sign in to the Microsoft Security Intelligence submission site to check for updates.
    5. If Microsoft identifies the file as a false positive and updates definitions, the file should no longer be flagged. If it continues to be flagged after definitions are updated, contact Microsoft Support.

    Notes:

    • Archive submissions can be encrypted with the password infected.
    • The maximum total size for uploaded files in the Defender portal is 500 MB.
    • Authenticated customers, especially enterprise customers with valid SAIDs, receive higher priority for analysis.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.