<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vlc.exe marked as W32.975C0D48C4.RET.SBX.TG in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814020#M7463</link>
    <description>&lt;P&gt;IIRC that's VLC&lt;/P&gt;
&lt;P&gt;Root cause for "what is going on" isn't done yet... I'll post it in the community if it gets sent to me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2023 19:24:13 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2023-04-13T19:24:13Z</dc:date>
    <item>
      <title>vlc.exe marked as W32.975C0D48C4.RET.SBX.TG</title>
      <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4813844#M7451</link>
      <description>&lt;DIV&gt;&lt;H3&gt;&lt;SPAN class=""&gt;False positive? &amp;nbsp;Just got a bunch of these off multiple MXs.&lt;/SPAN&gt;&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;MD5 : 346cac4d1166ef87ab7617fc977f7dd4&lt;/DIV&gt;&lt;DIV&gt;SHA-1 d4bf1fc804bef6293d867c5f250191860044639c&lt;/DIV&gt;&lt;DIV&gt;SHA-256 975c0d48c41d2ad76a242d5f7270f4bf8063bb9c753b375ab2c47c9e2060f562&lt;/DIV&gt;&lt;DIV&gt;Vhash 3872fcc78e34962257f24cc7728ffae1&lt;/DIV&gt;&lt;DIV&gt;SSDEEP 12288:ytHbQKCiPwXtnn9X25lauYsoRy5T9LlHbAlZ2A1w/ccW9ZbGwHbK+L65E7heqTxm:GhPwXtn9X25lvoUna2/clhK+L3EqRzi&lt;/DIV&gt;&lt;DIV&gt;TLSH T1F41512D014A648EBC530523EDC105E32B8A214885FB157F473F2B56EDADADB8E056FCA&lt;/DIV&gt;&lt;DIV&gt;File type ZIP&lt;/DIV&gt;&lt;DIV&gt;Magic data&lt;/DIV&gt;&lt;DIV&gt;TrID MSIX Windows app package (84.1%) &amp;nbsp; ZIP compressed archive (12.6%) &amp;nbsp; PrintFox/Pagefox bitmap (640x800) (3.1%)&lt;/DIV&gt;&lt;DIV&gt;File size 885.40 KB (906653 bytes)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;H4&gt;Processes Tree:&amp;nbsp;4008 - VLC&lt;/H4&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Endpoint:&amp;nbsp;&lt;/P&gt;&lt;H3&gt;&lt;SPAN class=""&gt;1d.tlu.dl.delivery.mp.microsoft.com&lt;/SPAN&gt;&lt;/H3&gt;&lt;/DIV&gt;&lt;DIV&gt;SHA256 : 975c0d48c41d2ad76a242d5f7270f4bf8063bb9c753b375ab2c47c9e2060f562&lt;/DIV&gt;&lt;DIV&gt;Disposition : Malicious&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Type : ZIP&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Size : 906653 bytes&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 13 Apr 2023 15:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4813844#M7451</guid>
      <dc:creator>brentb2529</dc:creator>
      <dc:date>2023-04-13T15:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: vlc.exe marked as W32.975C0D48C4.RET.SBX.TG</title>
      <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4813849#M7453</link>
      <description>&lt;P&gt;yep, FP, they just cleared that one.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 15:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4813849#M7453</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-04-13T15:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: vlc.exe marked as W32.975C0D48C4.RET.SBX.TG</title>
      <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814011#M7459</link>
      <description>&lt;P&gt;So what is it?&amp;nbsp; I got 5000 emails from a customer across their entire network.&amp;nbsp; We had to shutdown FMC altogether.&amp;nbsp; What's going on?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 18:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814011#M7459</guid>
      <dc:creator>Jeff Cooper</dc:creator>
      <dc:date>2023-04-13T18:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: vlc.exe marked as W32.975C0D48C4.RET.SBX.TG</title>
      <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814014#M7460</link>
      <description>&lt;P&gt;I'm wondering which SHA-256 are you getting alerted?&lt;/P&gt;
&lt;P&gt;Also if this matches the initial one, I would suggest you open a TAC case with FMC, since this SHA-256 is already marked as clean, and probably is not being populated to your device, correctly.&lt;/P&gt;
&lt;P&gt;SHA-256:&amp;nbsp;&lt;SPAN&gt;975c0d48c41d2ad76a242d5f7270f4bf8063bb9c753b375ab2c47c9e2060f562&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pedro M.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 19:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814014#M7460</guid>
      <dc:creator>pmedinac</dc:creator>
      <dc:date>2023-04-13T19:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: vlc.exe marked as W32.975C0D48C4.RET.SBX.TG</title>
      <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814020#M7463</link>
      <description>&lt;P&gt;IIRC that's VLC&lt;/P&gt;
&lt;P&gt;Root cause for "what is going on" isn't done yet... I'll post it in the community if it gets sent to me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 19:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814020#M7463</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-04-13T19:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: vlc.exe marked as W32.975C0D48C4.RET.SBX.TG</title>
      <link>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814129#M7467</link>
      <description>&lt;P&gt;This appears to have killed my FMC, I have awoken to the /Volume being 100% full and FMC not functioning.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 23:07:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/vlc-exe-marked-as-w32-975c0d48c4-ret-sbx-tg/m-p/4814129#M7467</guid>
      <dc:creator>Damon Kalajzich</dc:creator>
      <dc:date>2023-04-13T23:07:21Z</dc:date>
    </item>
  </channel>
</rss>

