<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malware disposition changes to Unknown randomly in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3232034#M4800</link>
    <description>&lt;P&gt;Hi, thanks for the response, but i didnt get it, why disposition changes to unknown at 19:27 when it was already declared malware before?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Dec 2017 04:25:16 GMT</pubDate>
    <dc:creator>syed.mohsin</dc:creator>
    <dc:date>2017-12-14T04:25:16Z</dc:date>
    <item>
      <title>Malware disposition changes to Unknown randomly</title>
      <link>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3227780#M4739</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi, We have deployed ASA since last few months, everything is working fine, but we have observe that sometimes if a file is declared Malware disposition from Cisco Cloud, it randomly changes to 'unknown' and that malicious file passed on to internal network with action Malware cloud lookup. Due to this abnormal behavior we are receiving multiple malicious file passing from ASA. Snapshot is attached.&lt;/P&gt;
&lt;P&gt;FMC Version:6.2.1 (build 342)&lt;/P&gt;
&lt;P&gt;ASA Version 9.5&lt;/P&gt;
&lt;P&gt;Why Malware disposition changes randomly to Unknown? Is this normal behavior?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3227780#M4739</guid>
      <dc:creator>syed.mohsin</dc:creator>
      <dc:date>2019-03-09T01:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Malware disposition changes to Unknown randomly</title>
      <link>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3231438#M4771</link>
      <description>&lt;P&gt;Hi Syed,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to answer your question, we will need the SHA-256 of that file&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 10:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3231438#M4771</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2017-12-13T10:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Malware disposition changes to Unknown randomly</title>
      <link>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3231446#M4781</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Check this hash:&lt;/P&gt;
&lt;P&gt;SHA 256: a1b9d6fa618ce38eb3554d76868f7259a61be8cd11d4a8a5c9e91eb29ba23a67&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached is the snapshot:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 10:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3231446#M4781</guid>
      <dc:creator>syed.mohsin</dc:creator>
      <dc:date>2017-12-13T10:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Malware disposition changes to Unknown randomly</title>
      <link>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3231560#M4791</link>
      <description>&lt;P&gt;This file has been submitted to Threatgrid 12/13/2017 2:12:31 pm. The disposition is done by Synthetic Event Engine that convicts binaries based upon actions of several Indicator of Compromise in a SANDBOX. For further reference over this sample with disposition malicious, see&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.talosintelligence.com/amp-naming/" target="_blank"&gt;https://www.talosintelligence.com/amp-naming/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;SBX.VIOC- detection engine - Syntetic events&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you have access to the threatgrid account hereby the link, which contains the video+report of the IOC actions.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://panacea.threatgrid.com/mask/#/submission/e5f4ab6d542cb7a2ae9d24349f6296f9" target="_blank"&gt;https://panacea.threatgrid.com/mask/#/submission/e5f4ab6d542cb7a2ae9d24349f6296f9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Let me know if you need further info to this&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 13:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3231560#M4791</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2017-12-13T13:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: Malware disposition changes to Unknown randomly</title>
      <link>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3232034#M4800</link>
      <description>&lt;P&gt;Hi, thanks for the response, but i didnt get it, why disposition changes to unknown at 19:27 when it was already declared malware before?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 04:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/malware-disposition-changes-to-unknown-randomly/m-p/3232034#M4800</guid>
      <dc:creator>syed.mohsin</dc:creator>
      <dc:date>2017-12-14T04:25:16Z</dc:date>
    </item>
  </channel>
</rss>

