Forum Discussion
SmartScreen reputation issue for EV Code Signed Windows application
Hello Microsoft Defender Threat Intelligence Team,
We are the developer of a legitimate Windows desktop application called "ShangJing".
Recently, our users reported that Microsoft Defender SmartScreen displays the following warning when downloading and launching our application:
"Microsoft Defender SmartScreen can't verify this file is safe."
The application is not malicious and has been digitally signed with a GlobalSign EV Code Signing Certificate.
Application information:
Product Name:
ShangJing
Publisher:
Zhaoyi Information Technology (Shanghai) Co., Ltd.
Certificate:
GlobalSign EV Code Signing Certificate
File:
尚镜_2.0.0_platinum_setup.exe
Issue:
Users receive SmartScreen reputation warning when downloading our application.
We have already submitted the file through Microsoft Security Intelligence submission portal 7 days ago, but we have not received any update yet.
Submission ID:
0c015296-b9cf-4130-9eaf-fc59cd145370
The file is distributed through our official website:
https://www.changine.cn/downloads
We would like to understand:
1. Is this caused by insufficient SmartScreen reputation for a newly released binary?
2. Is there any additional verification required from the software publisher side?
3. How can we ensure our legitimate application gains proper SmartScreen reputation?
Our application is widely used for live streaming and camera-related workflows. It does not contain any malicious behavior.
We would appreciate any guidance from the Microsoft team.
Thank you.
1 Reply
An EV certificate no longer guarantees SmartScreen reputation. Microsoft evaluates publisher reputation and the file hash, so a new installer can show an unrecognized-app warning even when its signature is valid.
Verify that the downloaded file retains a valid Authenticode signature, trusted timestamp, expected publisher name, and unchanged hash. Sign every executable with the same publisher identity, timestamp each signature, and never modify the package afterward.
Submitting the file through Microsoft Security Intelligence is the correct escalation for a suspected false warning. Confirm that Microsoft Defender SmartScreen was selected and keep the submission ID. No public reputation threshold or guaranteed review time exists, so seven days alone does not indicate a decision.
Also confirm whether the message comes from SmartScreen, Smart App Control, or enterprise policy, since those controls can produce different blocks. If it remains unresolved, escalate through Microsoft support with the signed file hash and submission ID.