# StatsBase.jl package: Possible Trojan:Win32 /Wacatac.H!m?

**URL:** <https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410>\
**Category:** General Usage\
**Created:** [June 15, 2023, 5:31pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410 "2023-06-15T17:31:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![JJTex](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jjtex/32/46469_2.png) [@JJTex](https://discourse.julialang.org/u/JJTex)\
**Post date:** [June 15, 2023, 5:31pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/1 "2023-06-15T17:31:22Z")

</div>

Hello.  
My name is Jair, I’m Brazilian (Goiânia/GO), I’m using google translator for this conversation. as I’m new to Julia, I don’t know if this is where I make such an announcement: Today (06/15/2023) when adding the StatsBase.jl package in Julia v.1.9.1, the Windows antivirus blocked the installation action, claiming a possible Trojan:Win32 /Wacatac.H!ml.  
Does anyone know if this works? Is said package safe? I believe the same has been tested before. It is not?

Thank you in advance for your attention.

Jair Jose Teixeira

---

<div class="post-metadata">

**Author:** ![frylock](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/frylock/32/50213_2.png) [@frylock](https://discourse.julialang.org/u/frylock)\
**Post date:** [June 15, 2023, 5:50pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/2 "2023-06-15T17:50:13Z")

</div>

I don’t know anything about how Windows Defender works, but I’m guessing the search for binary patterns inside of downloads. It could be, that for whatever reason, StatsBase.jl happens to have that binary pattern in it, unrelated to malware at all.

This is just the first link for a google search with “how can I stop windows defender from marking my software as a trojan”:

> **[How to stop Windows Defender from mistaking legitimate files for trojans](https://www.techrepublic.com/article/how-to-stop-windows-defender-from-mistaking-legitimate-files-for-trojans/)**
>
> Several Windows users have reported that Windows Defender has detected real Windows files as Trojan:Win32/Bluteal.B!rfn. Here's how to fix the problem.

Perhaps a more useful link: how to submit a file to Microsoft for malware analysis:  
[https://www.microsoft.com/en-us/wdsi/filesubmission](https://www.microsoft.com/en-us/wdsi/filesubmission)

---

<div class="post-metadata">

**Author:** ![JJTex](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jjtex/32/46469_2.png) [@JJTex](https://discourse.julialang.org/u/JJTex)\
**Post date:** [June 15, 2023, 5:56pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/3 "2023-06-15T17:56:06Z")

</div>

Thanks. I will send this to Microsoft Security Intelligence.

---

<div class="post-metadata">

**Author:** ![frylock](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/frylock/32/50213_2.png) [@frylock](https://discourse.julialang.org/u/frylock)\
**Post date:** [June 15, 2023, 5:57pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/4 "2023-06-15T17:57:51Z")

</div>

That name sounds ominous doesn’t it: Microsoft Security Intelligence?

---

<div class="post-metadata">

**Author:** ![JJTex](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jjtex/32/46469_2.png) [@JJTex](https://discourse.julialang.org/u/JJTex)\
**Post date:** [June 15, 2023, 6:02pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/5 "2023-06-15T18:02:57Z")

</div>

Mr. frylock, I accessed the link, but you must send the package file.

But,…

How to stop Windows Defender from mistaking legitimate files for trojans é de 2018 !!!

---

<div class="post-metadata">

**Author:** ![frylock](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/frylock/32/50213_2.png) [@frylock](https://discourse.julialang.org/u/frylock)\
**Post date:** [June 15, 2023, 6:10pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/6 "2023-06-15T18:10:13Z")

</div>

Weird!  
I’ll try on my end. It was StatsBase.jl, the file right? Or some component of the package?  
relevant link [on this site](https://discourse.julialang.org/t/julia-juliaup-from-windows-store-flagged-as-virus-by-trend-micro-apex-one/99331).

---

<div class="post-metadata">

**Author:** ![JJTex](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jjtex/32/46469_2.png) [@JJTex](https://discourse.julialang.org/u/JJTex)\
**Post date:** [June 15, 2023, 6:30pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/7 "2023-06-15T18:30:44Z")

</div>

Mr. frylock,  
resolved case:

 ![image](https://global.discourse-cdn.com/julialang/original/3X/8/8/884677b95af1f0e6795ea4e228c5da8c79314af9.png)

---

<div class="post-metadata">

**Author:** ![JJTex](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jjtex/32/46469_2.png) [@JJTex](https://discourse.julialang.org/u/JJTex)\
**Post date:** [June 15, 2023, 6:31pm UTC](https://discourse.julialang.org/t/statsbase-jl-package-possible-trojan-win32-wacatac-h-m/100410/8 "2023-06-15T18:31:51Z")

</div>

Thank you for your attention.
