<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malicious File in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429189#M8074</link>
    <description>&lt;P&gt;Thank you for your help &lt;SPAN class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Apr 2018 13:07:21 GMT</pubDate>
    <dc:creator>Fire_Dragon</dc:creator>
    <dc:date>2018-04-06T13:07:21Z</dc:date>
    <item>
      <title>Malicious File</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429185#M8070</link>
      <description>&lt;P&gt;I was looking at some security events in my Meraki dashboard and it seems to be showing this malicious filename: W32.4E846BBEDE-95.SBX.TG when I visit the virus total link attached to this finding it gives me different information. I have googled this malicious filename and found that it was linked to a malicious Microsoft Powerpoint exe file. What I am trying to gather here is what exactly does this virus do to the system? Any information would help.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.virustotal.com/en/file/4e846bbede5e4a76cf1686c145a595d9cdfed95e598a5132e79f7f72cfda0e36/analysis/" target="_blank" rel="external nofollow noopener noreferrer"&gt;https://www.virustotal.com/en/file/4e846bbede5e4a76cf1686c145a595d9cdfed95e598a5132e79f7f72cfda0e36/analysis/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 00:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429185#M8070</guid>
      <dc:creator>Fire_Dragon</dc:creator>
      <dc:date>2018-04-06T00:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious File</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429186#M8071</link>
      <description>&lt;P&gt;Were there any other details?  I googled that filename and didn't find anything.  &lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 00:56:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429186#M8071</guid>
      <dc:creator>simple818</dc:creator>
      <dc:date>2018-04-06T00:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious File</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429187#M8072</link>
      <description>&lt;P&gt;Same here I looked everywhere and could not find anything on it. The virus total link I posted at the bottom said Roblox as the file name. I looked up this hash associated with the file &lt;SPAN&gt;4e846bbede5e4a76cf1686c145a595d9cdfed95e598a5132e79f7f72cfda0e36 and got this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.hybrid-analysis.com/sample/4e846bbede5e4a76cf1686c145a595d9cdfed95e598a5132e79f7f72cfda0e36" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.hybrid-analysis.com/sample/4e846bbede5e4a76cf1686c145a595d9cdfed95e598a5132e79f7f72cfda0e36&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 01:01:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429187#M8072</guid>
      <dc:creator>Fire_Dragon</dc:creator>
      <dc:date>2018-04-06T01:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious File</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429188#M8073</link>
      <description>&lt;P&gt;Microsoft classifies it as a PUA:Win32/InstallCore,&lt;/P&gt;&lt;P&gt;Summary&lt;/P&gt;&lt;DIV class="summaryText"&gt;&lt;DIV&gt;&lt;P class="x-hidden-focus"&gt;This application was stopped from running on your network because it has a poor reputation. This application can also affect the quality of your computing experience. We have seen this leading to the following potentially unwanted behaviors on PCs:&lt;/P&gt;&lt;P class="x-hidden-focus"&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adds files that run at startup&lt;/LI&gt;&lt;LI&gt;Modifies file associations&lt;/LI&gt;&lt;LI&gt;Injects into other processes on your system&lt;/LI&gt;&lt;LI&gt;Injects into browsers&lt;/LI&gt;&lt;LI&gt;Changes browser settings&lt;/LI&gt;&lt;LI&gt;Changes browser shortcuts&lt;/LI&gt;&lt;LI&gt;Installs browser extensions&lt;/LI&gt;&lt;LI&gt;Disables User Access Control (UAC)&lt;/LI&gt;&lt;/UL&gt;&lt;P class="x-hidden-focus"&gt;These applications are most commonly software bundlers or installers for applications such as toolbars, adware, or system optimizers. We have observed this application installing software that you might not have intended on your PC.&lt;/P&gt;&lt;P&gt;If you were trying to install an application, you might have downloaded it from a source other than the official product's website.&lt;/P&gt;&lt;P&gt;We usually see this application installed on PCs in the following countries. This list is sorted according to prevalence:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;United States&lt;/LI&gt;&lt;LI&gt;Brazil&lt;/LI&gt;&lt;LI&gt;France&lt;/LI&gt;&lt;LI&gt;Poland&lt;/LI&gt;&lt;LI&gt;Spain&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;A title="Source" href="https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=PUA:Win32/InstallCore" target="_self" rel="nofollow noopener noreferrer"&gt;Source&lt;/A&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 06 Apr 2018 07:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429188#M8073</guid>
      <dc:creator>Zedilt</dc:creator>
      <dc:date>2018-04-06T07:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Malicious File</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429189#M8074</link>
      <description>&lt;P&gt;Thank you for your help &lt;SPAN class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 13:07:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/malicious-file/m-p/5429189#M8074</guid>
      <dc:creator>Fire_Dragon</dc:creator>
      <dc:date>2018-04-06T13:07:21Z</dc:date>
    </item>
  </channel>
</rss>

