cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1363
Views
0
Helpful
1
Replies

infostealer-psexec.talos.sso

noahigros
Level 1
Level 1

In the last hour I've been receiving an uptick of alerts for w32.4173FC5A68.infostealer-psexec.talos.sso with the file path: 

File Path

Wscript.exe

file:///C%3A/Windows/System32/Wscript.exe

Some of the alerts have different command line arguments but the same .exe, One individual from the same agency had W32.DFC.MalParent which I assume is where it was possibly run from originally? 

Has anyone else been seeing this?

1 Accepted Solution

Accepted Solutions

noahigros
Level 1
Level 1

Update: Confirmed False Positive. Please see attached response from Cisco.

View solution in original post

1 Reply 1

noahigros
Level 1
Level 1

Update: Confirmed False Positive. Please see attached response from Cisco.